Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-60007: Eclipse Milo 0.6.0 to 1.1.4: Passwords can be stolen over the internet
CVE-2026-60007 · published 1 month ago
Summary
If an attacker intercepts a password-protected message sent over the internet, they can use repeated attempts to guess the password, allowing them to steal the password. This affects users of Eclipse Milo versions 0.6.0 to 1.1.4. To protect your users, update to a newer version of Eclipse Milo as soon as possible.
What to do
- Update eclipse milo to version 1.1.5 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| eclipse foundation | eclipse milo | <= 1.1.4 |
| eclipse | milo |
>= 0.6.0, < 1.1.5 cpe:2.3:a:eclipse:milo:*:*:*:*:*:*:*:* |
Original advisory text
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path att...
In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-60007 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/60xxx/CVE-2026-60007... Vendor Advisory
- https://github.com/eclipse-milo/milo/commit/db59fae993a3a1bc66fffc8a2796d444b402...
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/183
Internet-facing
60 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker partial control
Type
CWE-204Observable Response Discrepancy
Timeline
Published4 Aug 2026
Updated1 Oct 2026
First seen4 Aug 2026
Track software like this
Free during beta