CVE-2026-88819 PUBLISHED

Assigner: eclipse
Reserved: 10.09.2026 Published: 14.09.2026 Updated: 14.09.2026

In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor Eclipse Foundation
Product Eclipse Data Plane Core
Versions Default: unaffected
  • affected from a6f7d4cc0093931287c349e1e546ad2932c08e8d to 882fe22db42bc67abfd0304c4cdb141b762c35d1 (excl.)
  • affected from 0.1.0 to 0.1.3 (incl.)

Credits

  • Eclipse Foundation Security Team finder

References

Problem Types

  • CWE-290 Authentication bypass by spoofing CWE
  • CWE-345 Insufficient Verification of Data Authenticity CWE