CVE Explorer
CVE-2026-6272
A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest.
1. Obtain any valid token with only read scope.
2. Connect to the normal production gRPC API (kuksa.val.v2).
3. Open OpenProviderStream.
4. Send ProvideSignalRequest for a target signal ID.
5. Wait for the broker to forward GetProviderValueRequest.
6. Reply with attacker-controlled GetProviderValueResponse.
7. Other cli
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Eclipse KUKSA - Databroker","repo":"https://github.com/eclipse-kuksa/kuksa-databroker","vendor":"Eclipse Foundation","versions":[{"lessThanOrEqual":"0.6.0","status":"affected","version":"0.5.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a3c1c82db808e5eaa64dff26f1bc3a2f410ae30af63c20a82c62df7b0ea1673b · sha256:850030f618c39e61… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.5,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"N…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:a3c1c82db808e5eaa64dff26f1bc3a2f410ae30af63c20a82c62df7b0ea1673b · sha256:850030f618c39e61… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a3c1c82db808e5eaa64dff26f1bc3a2f410ae30af63c20a82c62df7b0ea1673b · sha256:850030f618c39e61… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://gitlab.eclipse.org/security/cve-assignment/-/issues/98"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a3c1c82db808e5eaa64dff26f1bc3a2f410ae30af63c20a82c62df7b0ea1673b · sha256:850030f618c39e61… · /containers/adp/0/references/0
{"url":"https://gitlab.eclipse.org/security/cve-assignment/-/issues/98"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a3c1c82db808e5eaa64dff26f1bc3a2f410ae30af63c20a82c62df7b0ea1673b · sha256:850030f618c39e61… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.