Security Flaw in Eclipse Che Affects File Access and Credential Forwarding
CVE-2026-86671

8.4HIGH

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-86671?

In Eclipse Che versions 7.29.0 and later, improper input validation in the GET /api/scm/resolve and POST /api/factory/resolver endpoints allows attackers to inject controlled URLs. This vulnerability enables any authenticated user to exploit local file access via the file:// scheme, including potentially exposing sensitive Kubernetes service-account tokens and other internal resources. Furthermore, attackers can leverage malicious devfiles to trigger unauthorized credential forwarding, exposing users' SCM personal access tokens without the need for direct API exploitation. Currently, there is no fix available for this vulnerability.

Affected Version(s)

Eclipse Che 7.29.0 < 7.123.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.