← All Advisories

Eclipse Milo OPC UA Username-Token Decryption Returns Distinguishable RSA Padding Errors, Exposing a Bleichenbacher Oracle via Unauthenticated ActivateSession Requests

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-60007

Key Details

CVECVE-2026-60007
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-08-05
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productseclipse milo
Classified asCWE-204 (Observable Response Discrepancy)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
eclipsemilo
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use repeated unauthenticated `ActivateSession` requests as a padding oracle, recover the victim's password, and authenticate with the recovered credentials.

What to Do

Monitor eclipse's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-60007
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-60007
Vendor advisoryhttps://gitlab.eclipse.org/security/cve-assignment/-/work_items/183