Junglewise Threat Intelligence

CVE-2026-88819: Eclipse Data Plane Core proof-of-possession bypass in JWT refresh

CVE-2026-88819 · Severity: info · Published 2026-09-14

Vendors: Eclipse.

Executive brief

Siglet, a token refresh service used in Tractus-X data exchange flows, fails to verify that a refresh request is signed by the legitimate client's private key. An attacker who obtains a leaked token pair can forge a valid refresh request using their own key, bypassing the security mechanism designed to prevent token theft. This allows indefinite access token renewal without the client's signing credentials.

Technical details

The vulnerability is a proof-of-possession (PoP) bypass in JwtTokenManager::renew() (CWE-290, CWE-345). The refresh handler accepts a bound token (JWT signed by the client with its DID-anchored private key) and verifies the signature using a DidWebVerificationKeyResolver that dereferences the issuer URL from the unverified JWT header. After signature verification, the code checks only that the JWT's subject claim matches the original token's subject, but never validates that the issuer (the key that actually signed the JWT) matches the expected client identity. An attacker with a stolen (refresh_token, access_token) pair can forge a bound token signed with an attacker-controlled keypair, publish the public key at a attacker-controlled did:web URL, and complete the refresh without ever possessing the legitimate client's private key. The flaw is reachable on the public endpoint (siglet/src/handler/refresh/mod.rs) with no authentication bypass required beyond token leakage. Patch status unknown from the advisory.

Affected products

  • Eclipse Data Plane Core 0.0.1 (all commits from a6f7d4c onwards; no release tags exist)

Timeline

  • 2026-09-14: disclosed: Published to NVD

References