Description
In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
Published: 2026-09-14
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access via hijacked refresh tokens
Action: Immediate Patch
AI Analysis

Impact

The Siglet component in Eclipse Data Plane Core lacks enforcement of proof of possession for the issuer DID when handling refresh tokens. This flaw means an attacker who has obtained a valid refresh token can use it without proving control over the issuer’s DID, effectively bypassing intended authentication checks. The impact is the potential for unauthorized access or privilege escalation within systems that rely on these refresh tokens for session continuity, compromising confidentiality and integrity of protected resources.

Affected Systems

Vendors impacted include Eclipse Foundation’s Eclipse Data Plane Core product line, specifically the Siglet module. Affected versions span current and past releases; the precise version range is not enumerated in the advisories.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, while EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, as an adversary can exploit a compromised refresh token over a network. Exploitation requires possession of a refresh token and does not rely on further system access, making the risk of compromise significant for deployments that do not enforce DID proof.

Generated by OpenCVE AI on September 15, 2026 at 13:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Eclipse Data Plane Core patch that enforces proof of possession of the issuer DID for refresh tokens.
  • If a patch is unavailable, adjust the refresh token handler configuration to require an active DID challenge before accepting refresh tokens to emulate proof of possession.
  • Restrict refresh token issuance to authenticated clients only, and monitor token usage for anomalies to detect potential misuse.

Generated by OpenCVE AI on September 15, 2026 at 13:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Title Refresh Token Handler Lacks Proof of Possession of Issuer DID in Siglet

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
Weaknesses CWE-290
CWE-345
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-14T19:23:00.453Z

Reserved: 2026-09-10T08:53:25.943Z

Link: CVE-2026-88819

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:15.992Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T16:17:22.240

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-88819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:15:18Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-345

    Insufficient Verification of Data Authenticity