CVE-2026-62927: Eclipse milo vulnerability
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Until upgrading to Eclipse Milo 1.1.5, restrict network access to the Milo server so only trusted/authorized clients can reach the Call service, preventing anonymous or low-privileged batching from reaching denied methods.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-62927?
CVE-2026-62927 has a risk score of 65, indicating a medium severity vulnerability.
How do I fix CVE-2026-62927?
To mitigate CVE-2026-62927, upgrade Eclipse Milo to version 1.1.5 or later, where the vulnerability has been addressed.
What versions of Eclipse Milo are affected by CVE-2026-62927?
Eclipse Milo versions from 1.0.0 to 1.1.4 are affected by CVE-2026-62927.
What type of vulnerability is CVE-2026-62927?
CVE-2026-62927 is an authorization vulnerability that allows unauthorized method execution by low-privileged clients.
When was CVE-2026-62927 published?
CVE-2026-62927 was published on August 4, 2026.