Access Control Vulnerability in Open VSX Deployment by Eclipse Foundation
CVE-2026-90882
8.7HIGH
What is CVE-2026-90882?
A misconfiguration in the Open VSX deployment allowed the Access-Control-Allow-Origin header to reflect the requesting origin, enabling illicit credentialed requests to authenticated /user endpoints. This flaw exposed sensitive user information, including login names and personal access tokens, allowing attackers to exfiltrate data without proper authorization. The vulnerability arises from the mismanagement of CORS settings, which inadvertently permitted cross-origin requests with credentials, potentially leading to severe data compromise.
Affected Version(s)
open-vsx.org 29/04/2026 <= 07/09/2026
