Access Control Vulnerability in Open VSX Deployment by Eclipse Foundation
CVE-2026-90882

8.7HIGH

Key Information:

Vendor
CVE Published:
22 September 2026

What is CVE-2026-90882?

A misconfiguration in the Open VSX deployment allowed the Access-Control-Allow-Origin header to reflect the requesting origin, enabling illicit credentialed requests to authenticated /user endpoints. This flaw exposed sensitive user information, including login names and personal access tokens, allowing attackers to exfiltrate data without proper authorization. The vulnerability arises from the mismanagement of CORS settings, which inadvertently permitted cross-origin requests with credentials, potentially leading to severe data compromise.

Affected Version(s)

open-vsx.org 29/04/2026 <= 07/09/2026

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

https://github.com/Char0n1507
.