PT-2026-53258 · Eclipse Foundation+1 · Eclipse Csi - Pia+1

CVE-2026-12616

·

Published

2026-06-29

·

Updated

2026-06-29

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PIA (affected versions not specified)
Description An unauthenticated attacker can forge log records that are indistinguishable from genuine authentication success messages. This occurs because the '/v1/upload/sbom' endpoint extracts the iss claim from a supplied JWT without signature verification and interpolates it into log statements before validation. Since the log format renders newlines literally, this allows the injection of fake entries, undermining the audit trail used for incident response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12616

Affected Products

Eclipse Csi - Pia
Pia