๐Ÿ” CVE Alert

CVE-2026-18918

UNKNOWN 0.0

OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilter`, are vulnerable. An attacked can create a provisional trusted client (valid use-case) but then it can be used as a trusted client immediately without requiring the administrator approval to clear the provisional status. The 3-legged path requiring user interaction is not vulnerable and rejects provisional clients.

CWE CWE-863
Vendor eclipse foundation
Product eclipse lyo
Published Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse lyo

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse lyo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Lyo
2.0.0 < 7.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-lyo/lyo/releases/tag/v6.0.1.Final github.com: https://github.com/eclipse-lyo/lyo/releases/tag/v7.0.0.Beta3 gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/221

Credits

Eclipse Foundation Security Team