{"id":"CVE-2026-60007","published":"2026-08-04T13:18:55.427","lastModified":"2026-08-05T20:22:16.417","description":"In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.","cvssScore":7.4,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-204"],"vendors":["eclipse"],"products":["milo"],"references":[{"url":"https://github.com/eclipse-milo/milo/commit/db59fae993a3a1bc66fffc8a2796d444b40285fb","tags":["Patch"]},{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/183","tags":["Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598","tags":["Issue Tracking","Vendor Advisory"]}],"exploitRefs":[{"url":"https://github.com/eclipse-milo/milo/commit/db59fae993a3a1bc66fffc8a2796d444b40285fb","tags":["Patch"]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker to perform a padding oracle attack on RSA PKCS#1 v1.5 padding in `Basic128Rsa15`-encrypted username tokens, enabling password recovery and unauthorized access.","exploitability":"Exploitation requires capturing the victim's token and sending repeated unauthenticated `ActivateSession` requests; on-path attacker position is necessary.","blast_radius":"If exploited, this could lead to full compromise of affected Eclipse Milo systems, including potential unauthorized access by attackers.","remediation":"Update to Eclipse Milo versions later than 1.1.4 immediately.","tags":["auth-bypass","padding-oracle","rsa","encryption"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:59:58.040Z"}}