OAuth Authorization Bypass in Eclipse Lyo Versions Affects Trust Management
CVE-2026-18918
9.1CRITICAL
What is CVE-2026-18918?
In Eclipse Lyo versions 2.0.0 to 7.0.0, a vulnerability allows attackers to bypass OAuth server authorization checks when 2-legged authentication is enabled. This issue arises when applications rely on the AbstractAdapterCredentialsFilter for authorization filtering, enabling attackers to utilize a provisional trusted client without the administrator's approval. As a result, unauthorized access may be granted immediately, potentially compromising security. It is important to note that the 3-legged authentication flow remains secure and effectively rejects provisional clients.
Affected Version(s)
Eclipse Lyo 2.0.0 < 7.0.0
