Siglet Refresh Token Handler Lacks Proof of Possession (CVE-2026-88819)
CVE-2026-88819 Published on September 14, 2026
In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.
Vulnerability Analysis
CVE-2026-88819 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.
Weakness Types
Authentication Bypass by Spoofing
This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
Insufficient Verification of Data Authenticity
The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Affected Versions
Eclipse Foundation Eclipse Data Plane Core:- Version a6f7d4cc0093931287c349e1e546ad2932c08e8d and below 882fe22db42bc67abfd0304c4cdb141b762c35d1 is affected.
- Version 0.1.0, <= 0.1.3 is affected.