Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107503

Quick assessment

Affected
Eclipse Ditto Ditto Explorer UI
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

未经验证的客户端环境 URL 导致 OAuth 授权码和 PKCE 码验证器泄露,攻击者可利用注入的 OIDC 身份提供商配置接管用户账户。在 Eclipse Ditto 的 Ditto Explorer 应用(受影响的版本范围为 3.6.0 至 3.9.7)中,攻击者可通过构造恶意链接,设置一个由攻击者控制的 OIDC 身份提供商,并启用自动单点登录(autoSso)功能。 当用户点击该链接时,用户界面(UI)会向真正的身份提供商发起登录请求,但在获取授权码后,会与 PKCE 的 code_verifier 一起

CVSS 7.1 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
Eclipse Ditto Ditto Explorer UI 3.6.0≤ 3.9.7 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107503

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Unvalidated environments URL allows OAuth authorization code + PKCE verifier theft and account takeover via injected OIDC authority in Ditto Explorer in Eclipse Ditto Ditto Explorer [3.6.0,3.9.7] allows a craft link set an attacker-controlled OIDC authority with autoSso enabled. The UI then automatically starts a login at the genuine identity provider but exchanges the returned authorization code together with its PKCE code_verifier at an attacker-controlled token endpoint. This lets the attacker redeem the code for the victim's access and refresh tokens. Alternatively, an attacker-controlled api_uri causes the UI to send the victim's bearer token or Basic credentials to the attacker. Because the configuration is persisted, later visits to the UI without the crafted link repeat the token theft.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:H/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
系统设置或配置在外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Eclipse Ditto Ditto Explorer UI 3.6.0 ~ 3.9.7 -

II. Public POCs for CVE-2026-107503

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107503

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-107503 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107503

No comments yet


Leave a comment