What is CVE-2026-60007?
CVE-2026-60007 affects Eclipse Milo versions 0.6.0 through 1.1.4, where username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding versus other authentication failures. This allows an on-path attacker to repeatedly test a captured Basic128Rsa15-encrypted token to break its security. Affected systems should apply the security patch or reconfigure authentication mechanisms.
Azərbaycanca: CVE-2026-60007, Eclipse Milo-nun 0.6.0-dan 1.1.4-ə qədər versiyalarında istifadəçi adı token'i emalı zamanı RSA PKCS#1 v1.5 padding səhvi ilə digər autentifikasiya xətaları arasında fərqlənən cavablar qaytarır. Bu, şəbəkə üzərində olan hücumçuya qurbanın şifrəli token'ini təkrar sınaqla sındırmağa imkan yaradır. Təsirə məruz qalan sistemlərdə təhlükəsizlik yaması tətbiq edilməli və ya autentifikasiya mexanizmləri yenidən konfiqurasiya olunmalıdır.
Related CVEs
link basis: same weakness class CWE-287; shared vendor: Eclipse
FAQ2
Which Eclipse Milo versions are affected by CVE-2026-60007?
Eclipse Milo versions 0.6.0 through 1.1.4 are affected by this vulnerability.
How can an on-path attacker break the captured encrypted token in CVE-2026-60007?
The attacker leverages distinguishable responses between invalid RSA PKCS#1 v1.5 padding and other authentication errors during username-token processing to repeatedly test the captured encrypted token and break its security.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.