JSON Injection Flaw in Eclipse Ditto Connectivity Service
CVE-2026-82958

7.6HIGH

Key Information:

Vendor
CVE Published:
2 September 2026

What is CVE-2026-82958?

Eclipse Ditto versions 1.3.0 and 3.9.6 contain a JSON injection vulnerability in the ImplicitThingCreationMessageMapper of the connectivity service. This flaw arises when the system builds a CreateThing command by substituting unescaped placeholder values from inbound message headers into a JSON template. When an attacker controls the header value, they can exploit this vulnerability to inject malicious JSON structures, leading to unauthorized assignment of access-control policies on digital twins. Such exploits can grant attackers full read/write access, overriding legitimate policies without administrative intervention. This issue emphasizes the critical need for strict header value control and JSON escaping in device management systems.

Affected Version(s)

Eclipse Ditto 1.3.0 <= 3.9.6

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohamed Lemine Ahmed Jidou
.