CVE-2026-62927: High severity Eclipse milo vulnerability
Published Aug 4, 2026
·Updated
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
Affected Software
2 affected components
Eclipse milo>=1.0.0<=1.1.4
Eclipse milo>=1.0.0<1.1.5
Event History
Aug 4, 2026
CVE Published
via MITRE·11:57 AM
Data Sourced
via MITRE·11:57 AM
DescriptionWeakness
Data Sourced
via NVD·01:18 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-62927?
CVE-2026-62927 has a risk score of 65, indicating a medium severity vulnerability.
2
How do I fix CVE-2026-62927?
To mitigate CVE-2026-62927, upgrade Eclipse Milo to version 1.1.5 or later, where the vulnerability has been addressed.
3
What versions of Eclipse Milo are affected by CVE-2026-62927?
Eclipse Milo versions from 1.0.0 to 1.1.4 are affected by CVE-2026-62927.
4
What type of vulnerability is CVE-2026-62927?
CVE-2026-62927 is an authorization vulnerability that allows unauthorized method execution by low-privileged clients.
5
When was CVE-2026-62927 published?
CVE-2026-62927 was published on August 4, 2026.