{"id":"CVE-2026-62927","published":"2026-08-04T13:18:55.670","lastModified":"2026-08-05T20:29:49.017","description":"In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwes":["CWE-863"],"vendors":["eclipse"],"products":["milo"],"references":[{"url":"https://github.com/eclipse-milo/milo/commit/59b50bed094de0d18a130a48f3527254dc76105d","tags":["Patch"]},{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/178","tags":["Issue Tracking","Patch","Vendor Advisory"]},{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598","tags":["Issue Tracking","Vendor Advisory"]}],"exploitRefs":[{"url":"https://github.com/eclipse-milo/milo/commit/59b50bed094de0d18a130a48f3527254dc76105d","tags":["Patch"]}],"hasPoc":true,"ai":{"summary":"The flaw allows an anonymous or low-privileged client to execute a denied method by batching it with an allowed one, bypassing authorization checks.","exploitability":"Exploitation is moderately hard requiring specific batch manipulation and knowledge of allowed methods.","blast_radius":"If exploited, the impact is limited as it does not allow remote code execution or data exfiltration but can lead to unauthorized method execution.","remediation":"Update to Eclipse Milo version 1.1.5 or later which addresses this vulnerability.","tags":["auth-bypass","batching","ics"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:53:41.425Z"}}