What is CVE-2026-62927?
CVE-2026-62927 is an authorization bypass vulnerability in Eclipse Milo versions 1.0.0 to 1.1.4. An attacker can execute a denied method by batching it with an allowed method in the Call service, circumventing authorization checks. Users should upgrade to version 1.1.5 or later.
Azərbaycanca: CVE-2026-62927 Eclipse Milo-nun 1.0.0-dən 1.1.4-ə qədər versiyalarında Call servisində avtorizasiya bypass zəifliyidir. Təcavüzkar, icazəsi olmayan metodu icazəli metodla birlikdə batch şəklində göndərərək qadağan olunmuş əməliyyatı icra edə bilər. İstifadəçilər dərhal 1.1.5 və ya daha yüksək versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of Eclipse Milo are affected by CVE-2026-62927?
This authorization bypass vulnerability affects Eclipse Milo versions 1.0.0 to 1.1.4.
How can an attacker bypass authorization checks in the Call service using CVE-2026-62927?
An attacker can execute a denied method by batching it with an allowed method in the Call service, thereby circumventing authorization checks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.