Security Flaw in Eclipse Che Affects File Access and Credential Forwarding
CVE-2026-86671
8.4HIGH
What is CVE-2026-86671?
In Eclipse Che versions 7.29.0 and later, improper input validation in the GET /api/scm/resolve and POST /api/factory/resolver endpoints allows attackers to inject controlled URLs. This vulnerability enables any authenticated user to exploit local file access via the file:// scheme, including potentially exposing sensitive Kubernetes service-account tokens and other internal resources. Furthermore, attackers can leverage malicious devfiles to trigger unauthorized credential forwarding, exposing users' SCM personal access tokens without the need for direct API exploitation. Currently, there is no fix available for this vulnerability.
Affected Version(s)
Eclipse Che 7.29.0 < 7.123.0
