CVE-2026-78254
published 2026-09-07CVE-2026-78254: The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of…
PriorityP353high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.54%
43.7th percentile
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-the-middle attack. Additionally in the case of scp or the ftp task using ftps the server must pass the server identity checks performed by the tasks.
For ftp tasks not using ftps a malicious server could act as a machine-in-the-middle to provide malicious files.
Starting with Ant 1.10.18 both tasks will prevent writing outside of the destination directory by default. An option is available to disable this behavior in the unlikely case that the old behavior is required by existing build files.
Mitigations:
Users of scp and ftp (when using ftps) in any version of Ant should not bypass server identity checks. Users of ftp not using ftps should switch to ftps where possible.
All users are recommended to upgrade to Apache Ant 1.10.18, which fixes this issue.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | ant | < 1.10.18 | 1.10.18 |
| apache_software_foundation | apache_ant | >= 1.2 < 1.10.18 | 1.10.18 |
| debian | ant | — | — |
| javapackages-tools_201801 | maven-antrun-plugin | — | — |
| javapackages-tools_201801 | maven-script-interpreter | — | — |
| javapackages-tools_201801 | plexus-ant-factory | — | — |
| javapackages-tools_201801 | testng | — | — |
| jenkins | jenkins | — | — |
| mta | mta-cli-rhel9 | — | — |
| mta | mta-java-external-provider-rhel9 | — | — |
| ocp-tools-4 | jenkins-rhel8 | — | — |
| ocp-tools-4 | jenkins-rhel9 | — | — |
| pki-deps_10.6 | glassfish-jaxb | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The ftp and scp tasks of Apache Ant can download files from a remote server.
ghsa_unreviewed·2026-09-07
CVE-2026-78254 [HIGH] CWE-23 The ftp and scp tasks of Apache Ant can download files from a remote server.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-the-middle attack. Additionally in the case of scp or the ftp task using ftps the server must pass the server identity checks performed by the tasks.
For ftp tasks not using ftps a malicious server could act as a machine-in-the-middle to provide malicious files.
Starting with Ant 1.10.18 both tasks will prevent writing outside o
VulDB
Apache Software Foundation Apache Ant ftp/scp path traversal
vuldb·2026-09-06
CVE-2026-78254 [CRITICAL] Apache Software Foundation Apache Ant ftp/scp path traversal
A vulnerability was found in Apache Software Foundation Apache Ant. It has been rated as critical. The impacted element is an unknown function of the component ftp/scp. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-78254. The attack may be initiated remotely. There is no available exploit.
Red Hat
org.apache.ant/ant: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks
vendor_redhat·2026-09-07·CVSS 7.4
CVE-2026-78254 [HIGH] CWE-22 org.apache.ant/ant: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks
org.apache.ant/ant: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks
A flaw was found in Apache Ant. The ftp and scp tasks, used for downloading files, are vulnerable to a path traversal issue. A malicious remote server can exploit this by providing specially crafted relative paths, allowing it to write files outside the intended download directory. This could lead to an attacker overwriting arbitrary files on the system with the permissions of the user running Ant, potentially compromising the system's integrity.
Package: mta/mta-cli-rhel9 (Migration Toolkit for Applications 8) - Affected
Package: mta/mta-java-external-provider-rhel9 (Migration Toolkit for Applications 8) - Affected
Package: jenkins (OpenShift Developer Tools and Services) - Affected
Package:
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-78254 python-avro: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 python-avro: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 python-avro: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machi
Bugzilla
CVE-2026-78254 jflex: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 jflex: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 jflex: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-
Bugzilla
CVE-2026-78254 pdfbox: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 pdfbox: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 pdfbox: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in
Bugzilla
CVE-2026-78254 tomcat-jakartaee-migration: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 tomcat-jakartaee-migration: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 tomcat-jakartaee-migration: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be sub
Bugzilla
CVE-2026-78254 fop: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 fop: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 fop: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-th
Bugzilla
CVE-2026-78254 msv: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 msv: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 msv: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-th
Bugzilla
CVE-2026-78254 janino: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 janino: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 janino: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in
Bugzilla
CVE-2026-78254 cglib: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 cglib: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 cglib: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-
Bugzilla
CVE-2026-78254 cldr-emoji-annotation: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 cldr-emoji-annotation: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 cldr-emoji-annotation: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject
Bugzilla
CVE-2026-78254 replacer: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 replacer: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 replacer: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-
Bugzilla
CVE-2026-78254 jetty: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 jetty: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 jetty: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-
Bugzilla
CVE-2026-78254 jacoco: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
bugzilla·2026-09-11·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 jacoco: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
CVE-2026-78254 jacoco: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in
Bugzilla
CVE-2026-78254 org.apache.ant/ant: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks
bugzilla·2026-09-07·CVSS 7.4
CVE-2026-78254 [HIGH] CVE-2026-78254 org.apache.ant/ant: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks
CVE-2026-78254 org.apache.ant/ant: Apache Ant: Arbitrary file write via path traversal in ftp and scp tasks
The ftp and scp tasks of Apache Ant can download files from a remote server. A malicious server can provide relative paths that allow it to write outside of the dedicated target directory for the download, making it possible to overwrite files of the attacker's choice using the permissions of the user running Ant in versions prior to Ant 1.10.18.
In order to exploit this vulnerability, the server would either have to be malicious or be subject to a machine-in-the-middle attack. Additionally in the case of scp or the ftp task using ftps the server must pass the server identity checks performed by the tasks.
For ftp tasks not using ftps a malicious server could act as a machine-in
2026-09-07
Published