PT-2026-67696 · Eclipse Foundation · Eclipse Milo

·

CVE-2026-60007

·

Published

2026-08-04

·

Updated

2026-08-05

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Eclipse Milo versions 0.6.0 through 1.1.4
Description Username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures. This allows an on-path attacker who captures a victim's Basic128Rsa15-encrypted username token to use repeated unauthenticated ActivateSession requests as a padding oracle—a side-channel attack that reveals information about the plaintext by observing error responses—to recover the victim's password and authenticate with the recovered credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60007

Affected Products

Eclipse Milo