In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Eclipse Milo Batch Authorization Bypass Allows Unauthorized Method Execution |
Tue, 04 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 04 Aug 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse milo |
|
| Vendors & Products |
Eclipse
Eclipse milo |
Tue, 04 Aug 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published: 2026-08-04T11:57:59.822Z
Updated: 2026-08-04T15:02:34.431Z
Reserved: 2026-07-16T13:58:02.225Z
Link: CVE-2026-62927
Updated: 2026-08-04T14:28:22.434Z
No data.
No data.