CVE-2023-54342: Eclipse Equinox Osgi
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.
Affected products
- Eclipse Equinox Osgi: from 3.8, up to and including 3.18
Published 2026-05-05. Last modified 2026-09-30.