High severity7.5NVD Advisory· Published Aug 4, 2026· Updated Aug 5, 2026
CVE-2026-62927
CVE-2026-62927
Description
In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/eclipse-milo/milo/commit/59b50bed094de0d18a130a48f3527254dc76105dnvdPatch
- gitlab.eclipse.org/security/cve-assignment/-/work_items/178nvdIssue TrackingPatchVendor Advisory
- gitlab.eclipse.org/security/vulnerability-reports/-/work_items/598nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.