Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-78254: CWE-23 Relative path traversal in Apache Software Foundation Apache Ant

0
High
VulnerabilityCVE-2026-78254cvecve-2026-78254cwe-23
Published: 09/07/2026 (09/07/2026, 07:41:54 UTC)
Source: CVE Database V5
Vendor/Project: Apache Software Foundation
Product: Apache Ant

Description

CVE-2026-78254 is a relative path traversal vulnerability in Apache Ant's ftp and scp tasks that allows a malicious server to write files outside the intended download directory. This can lead to overwriting arbitrary files with the permissions of the user running Ant in versions prior to 1.10.18. Exploitation requires a malicious or man-in-the-middle server, with additional server identity checks needed for scp and ftps. Apache Ant 1.10.18 addresses this issue by preventing writes outside the destination directory by default.

Affected software

Apache Software Foundation/org.apache.ant:ant
pkg:maven/Apache Software Foundation/org.apache.ant:ant
Affected versions
>=1.2 <1.10.18

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 08:38:35 UTC

Technical Analysis

The ftp and scp tasks in Apache Ant versions prior to 1.10.18 can be exploited via relative path traversal by a malicious or man-in-the-middle server to write files outside the designated target directory. This allows overwriting arbitrary files with the privileges of the user running Ant. The vulnerability requires the server to pass identity checks for scp and ftps tasks; for ftp without ftps, a man-in-the-middle can provide malicious files. Apache Ant 1.10.18 fixes this by enforcing directory write restrictions by default, with an option to disable this behavior if needed.

Potential Impact

An attacker controlling or intercepting the remote server can overwrite arbitrary files on the local system where Apache Ant runs, using the permissions of the Ant user. This could lead to unauthorized file modification or code execution depending on the overwritten files and user privileges.

Mitigation Recommendations

Users should upgrade to Apache Ant 1.10.18 or later, which includes a fix preventing writes outside the destination directory by default. Users of scp and ftp with ftps must not bypass server identity checks. For ftp without ftps, switching to ftps is recommended to prevent man-in-the-middle attacks. If upgrading is not immediately possible, ensure strict server identity verification and avoid unencrypted ftp where feasible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
apache
Date Reserved
2026-08-24T07:17:27.205Z
Cvss Version
null
State
PUBLISHED
Remediation Level
null

Threat ID: 6a9e6d62acd9273b493040cd

Added to database: 09/07/2026, 07:53:06 UTC

Last enriched: 09/07/2026, 08:38:35 UTC

Last updated: 09/07/2026, 08:38:35 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses