CVE-2026-78299

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.

  • Published Sep 14, 2026
  • CVSS 9.1 critical
  • 0.5% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-78299 at the National Vulnerability Database