HarborGuard / CVE
Back to search
HIGHCVE-2026-6272Published Modified CNA eclipse

CVE-2026-6272: A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa

A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open OpenProviderStream. 4. Send ProvideSignalRequest for a target signal ID. 5. Wait for the broker to forward GetProviderValueRequest. 6. Reply with attacker-controlled GetProviderValueResponse. 7. Other clients performing GetValue / GetValues for that signal receive forged data.

Metrics

CVSS v4.0
8.5
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • Eclipse Foundation / Eclipse KUKSA - Databroker
    ≤ 0.6.0
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H