In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
References
| Link | Resource |
|---|---|
| https://github.com/eclipse-milo/milo/commit/59b50bed094de0d18a130a48f3527254dc76105d | Patch |
| https://gitlab.eclipse.org/security/cve-assignment/-/work_items/178 | Issue Tracking Patch Vendor Advisory |
| https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 | Issue Tracking Vendor Advisory |
Configurations
History
05 Aug 2026, 20:29
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/eclipse-milo/milo/commit/59b50bed094de0d18a130a48f3527254dc76105d - Patch | |
| References | () https://gitlab.eclipse.org/security/cve-assignment/-/work_items/178 - Issue Tracking, Patch, Vendor Advisory | |
| References | () https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598 - Issue Tracking, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| First Time |
Eclipse milo
Eclipse |
|
| CPE | cpe:2.3:a:eclipse:milo:*:*:*:*:*:*:*:* |
04 Aug 2026, 13:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-04 13:18
Updated : 2026-08-05 20:29
NVD link : CVE-2026-62927
Mitre link : CVE-2026-62927
CVE.ORG link : CVE-2026-62927
JSON object : View
Products Affected
eclipse
- milo
CWE
CWE-863
Incorrect Authorization
