CVE-2026-60007: Eclipse milo vulnerability
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's Basic128Rsa15-encrypted username token to use repeated unauthenticated ActivateSession requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60007?
CVE-2026-60007 has a risk score of 76, indicating it is a high-severity vulnerability.
How do I fix CVE-2026-60007?
To remediate CVE-2026-60007, upgrade to Eclipse Milo versions 1.1.5 or later, where the issue has been addressed.
What type of vulnerability is CVE-2026-60007?
CVE-2026-60007 is a security vulnerability related to improper error handling during username-token processing.
Who is affected by CVE-2026-60007?
Eclipse Milo users running versions 0.6.0 through 1.1.4 are affected by CVE-2026-60007.
What can an attacker do with CVE-2026-60007?
An on-path attacker can exploit CVE-2026-60007 to perform unauthenticated attacks by leveraging distinguishable error messages.