PT-2026-53258 · Eclipse Foundation+1 · Eclipse Csi - Pia+1
CVE-2026-12616
·
Published
2026-06-29
·
Updated
2026-06-29
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PIA (affected versions not specified)
Description
An unauthenticated attacker can forge log records that are indistinguishable from genuine authentication success messages. This occurs because the '/v1/upload/sbom' endpoint extracts the
iss claim from a supplied JWT without signature verification and interpolates it into log statements before validation. Since the log format renders newlines literally, this allows the injection of fake entries, undermining the audit trail used for incident response.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eclipse Csi - Pia
Pia