PatchSiren

Eclipse Ditto CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Eclipse Ditto CVE published 2026-10-08

CVE-2026-107503

CVE-2026-107503 is a high-severity vulnerability in Eclipse Ditto's Ditto Explorer UI, affecting versions between 3.6.0 and 3.9.7. An attacker can exploit this vulnerability by crafting a link that sets an attacker-controlled OIDC authority with autoSso enabled, allowing for OAuth authorization code and PKCE verifier theft, and potentially leading to account takeover.