CVE-2026-78254: CWE-23 Relative path traversal in Apache Software Foundation Apache Ant
CVE-2026-78254 is a relative path traversal vulnerability in Apache Ant's ftp and scp tasks that allows a malicious server to write files outside the intended download directory. This can lead to overwriting arbitrary files with the permissions of the user running Ant in versions prior to 1.10.18. Exploitation requires a malicious or man-in-the-middle server, with additional server identity checks needed for scp and ftps. Apache Ant 1.10.18 addresses this issue by preventing writes outside the destination directory by default.
AI Analysis
Technical Summary
The ftp and scp tasks in Apache Ant versions prior to 1.10.18 can be exploited via relative path traversal by a malicious or man-in-the-middle server to write files outside the designated target directory. This allows overwriting arbitrary files with the privileges of the user running Ant. The vulnerability requires the server to pass identity checks for scp and ftps tasks; for ftp without ftps, a man-in-the-middle can provide malicious files. Apache Ant 1.10.18 fixes this by enforcing directory write restrictions by default, with an option to disable this behavior if needed.
Potential Impact
An attacker controlling or intercepting the remote server can overwrite arbitrary files on the local system where Apache Ant runs, using the permissions of the Ant user. This could lead to unauthorized file modification or code execution depending on the overwritten files and user privileges.
Mitigation Recommendations
Users should upgrade to Apache Ant 1.10.18 or later, which includes a fix preventing writes outside the destination directory by default. Users of scp and ftp with ftps must not bypass server identity checks. For ftp without ftps, switching to ftps is recommended to prevent man-in-the-middle attacks. If upgrading is not immediately possible, ensure strict server identity verification and avoid unencrypted ftp where feasible.
CVE-2026-78254: CWE-23 Relative path traversal in Apache Software Foundation Apache Ant
Description
CVE-2026-78254 is a relative path traversal vulnerability in Apache Ant's ftp and scp tasks that allows a malicious server to write files outside the intended download directory. This can lead to overwriting arbitrary files with the permissions of the user running Ant in versions prior to 1.10.18. Exploitation requires a malicious or man-in-the-middle server, with additional server identity checks needed for scp and ftps. Apache Ant 1.10.18 addresses this issue by preventing writes outside the destination directory by default.
Affected software
pkg:maven/Apache Software Foundation/org.apache.ant:antRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ftp and scp tasks in Apache Ant versions prior to 1.10.18 can be exploited via relative path traversal by a malicious or man-in-the-middle server to write files outside the designated target directory. This allows overwriting arbitrary files with the privileges of the user running Ant. The vulnerability requires the server to pass identity checks for scp and ftps tasks; for ftp without ftps, a man-in-the-middle can provide malicious files. Apache Ant 1.10.18 fixes this by enforcing directory write restrictions by default, with an option to disable this behavior if needed.
Potential Impact
An attacker controlling or intercepting the remote server can overwrite arbitrary files on the local system where Apache Ant runs, using the permissions of the Ant user. This could lead to unauthorized file modification or code execution depending on the overwritten files and user privileges.
Mitigation Recommendations
Users should upgrade to Apache Ant 1.10.18 or later, which includes a fix preventing writes outside the destination directory by default. Users of scp and ftp with ftps must not bypass server identity checks. For ftp without ftps, switching to ftps is recommended to prevent man-in-the-middle attacks. If upgrading is not immediately possible, ensure strict server identity verification and avoid unencrypted ftp where feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-08-24T07:17:27.205Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a9e6d62acd9273b493040cd
Added to database: 09/07/2026, 07:53:06 UTC
Last enriched: 09/07/2026, 08:38:35 UTC
Last updated: 09/07/2026, 08:38:35 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.