Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-18918 – OAuth Authentication Bypass – Eclipse Lyo 2.0.0 through 7.0.0.Beta2

Be the first to know when new zero-days emerge:

Summary

CVE-2026-18918 is a critical authorization bypass vulnerability in Eclipse Lyo affecting versions 2.0.0 through 7.0.0 when two-legged OAuth authentication is enabled. The flaw allows an attacker to register a provisional trusted OAuth client and use it immediately, without administrator approval, effectively circumventing authentication controls enforced by AbstractAdapterCredentialsFilter. The issue carries a CVSS score of 9.1 (Critical) and is remotely exploitable over the network with no privileges or user interaction required.

Technical details

  • Root cause: Eclipse Lyo’s OAuth implementation permits a client to be registered as a "provisional" trusted client and used immediately, before an administrator has reviewed or approved it. Security filters based on AbstractAdapterCredentialsFilter rely on this trust status to gate access, so the premature trust grant results in an authorization/authentication bypass (CWE-863: Incorrect Authorization).
  • Trigger conditions: The affected server must have two-legged OAuth authentication enabled for its OSLC adapter/consumer integrations.
  • Attack vector: Network-based; an attacker registers a rogue OAuth client against the vulnerable Lyo server and immediately uses the provisional trust granted to that client to authenticate as if it were an approved/trusted consumer.
  • Impact: Successful exploitation allows an unauthenticated or low-privileged attacker to bypass the intended administrator-approval workflow for trusted OAuth clients, gaining unauthorized access to protected resources served by the Lyo-based application (impacting confidentiality and integrity of OSLC resource data).
  • Classification: CWE-863 (Incorrect Authorization); mapped attack pattern CAPEC-114 (Authentication Abuse/Spoofing).

Affected software

  • Eclipse Lyo versions 2.0.0 through 7.0.0 (inclusive of pre-release/beta builds prior to the fixed releases) where two-legged OAuth authentication is enabled.

Severity

  • CVSS v4.0 Base Score: 9.1 (Critical)
  • Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/AU:Y/R:U/V:C/RE:L/U:Red
  • Key characteristics: Network attack vector, low attack complexity, no privileges required, no user interaction, high impact to confidentiality and integrity.

Mitigation and recommended actions

  • Immediate: Upgrade to Eclipse Lyo v6.0.1.Final or v7.0.0.Beta3 (or later), both of which contain fixes that prevent provisional/unapproved OAuth clients from being used before administrator approval and correct the trust-checking logic in AbstractAdapterCredentialsFilter.
  • If patching is not immediately possible:
    • Disable two-legged OAuth authentication on Lyo-based OSLC adapters/consumers until the patch can be applied.
    • Review and audit any currently registered OAuth clients/consumers for unexpected or unapproved entries, and revoke trust for any client that was not explicitly approved by an administrator.
    • Restrict network access to Lyo OSLC adapter endpoints (e.g., via firewall rules or reverse proxy allow-lists) to trusted internal networks while remediation is in progress.
    • Monitor authentication and consumer-registration logs for anomalous OAuth client registration activity.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge