JSON Injection Flaw in Eclipse Ditto Connectivity Service
CVE-2026-82958
What is CVE-2026-82958?
Eclipse Ditto versions 1.3.0 and 3.9.6 contain a JSON injection vulnerability in the ImplicitThingCreationMessageMapper of the connectivity service. This flaw arises when the system builds a CreateThing command by substituting unescaped placeholder values from inbound message headers into a JSON template. When an attacker controls the header value, they can exploit this vulnerability to inject malicious JSON structures, leading to unauthorized assignment of access-control policies on digital twins. Such exploits can grant attackers full read/write access, overriding legitimate policies without administrative intervention. This issue emphasizes the critical need for strict header value control and JSON escaping in device management systems.
Affected Version(s)
Eclipse Ditto 1.3.0 <= 3.9.6
