In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
References
| Link | Resource |
|---|---|
| https://github.com/eclipse-milo/milo/commit/59b50bed094de0d18a130a48f3527254dc76105d | Patch |
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/178 | Issue Tracking Patch Vendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-04 13:18
Updated : 2026-08-05 20:29
NVD link : CVE-2026-62927
Mitre link : CVE-2026-62927
CVE.ORG link : CVE-2026-62927
JSON object : View
Products Affected
eclipse
- milo
CWE
CWE-863
Incorrect Authorization
