{"id":"CVE-2026-88819","title":"In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.","summary":"In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.","severity":"medium","cvss":6.3,"cvssVector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-290","CWE-345"],"vendor":"Eclipse Foundation","product":"Eclipse Data Plane Core","affected":["eclipse_data_plane_core >= a6f7d4cc0093931287c349e1e546ad2932c08e8d < 882fe22db42bc67abfd0304c4cdb141b762c35d1","eclipse_data_plane_core >= 0.1.0 <= 0.1.3"],"published":"2026-09-14","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:38:33.883","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88819","references":[{"url":"https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/931","label":"emo@eclipse.org"}],"tags":["nvd","cve.org"],"epss":0.00124,"epssPercentile":0.02445,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T19:12:37.702936Z"},"cvssSource":"cna","ingestedAt":"2026-09-14T17:11:16.566Z","slug":"CVE-2026-88819","body":"## Overview\n\nIn Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":203103,"id":"CVE-2026-88819","ts":1789409574854,"field":"cvss","old":null,"new":"6.3"},{"seq":203102,"id":"CVE-2026-88819","ts":1789409574854,"field":"severity","old":"none","new":"medium"}]}