CVE-2026-18918
OAuth 1.0 session-fixation chain via unauthenticated provisional-consumer registration and insecure v1_0Allowed default
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server. In those cases, application that based their authz filters upon Lyo-provided `AbstractAdapterCredentialsFilter`, are vulnerable. An attacked can create a provisional trusted client (valid use-case) but then it can be used as a trusted client immediately without requiring the administrator approval to clear the provisional status. The 3-legged path requiring user interaction is not vulnerable and rejects provisional clients.
| CWE | CWE-863 |
| Vendor | eclipse foundation |
| Product | eclipse lyo |
| Published | Aug 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for eclipse foundation eclipse lyo
Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse lyo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Eclipse Foundation / Eclipse Lyo
2.0.0 < 7.0.0
References
Credits
Eclipse Foundation Security Team