CVE-2026-6272
Last modified
CVE-2026-6272 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A client holding only a read JWT scope can still register itself as a signal provider through the production kuksa.val.v2 OpenProviderStream API by sending ProvideSignalRequest. 1. Obtain any valid token with only read scope. 2. Connect to the normal production gRPC API (kuksa.val.v2). 3. Open OpenProviderStream. 4. Send ProvideSignalRequest for a target signal ID. 5. Wait for the broker to forward GetProviderValueRequest. 6. Reply with attacker-controlled GetProviderValueResponse. 7. Other clients performing GetValue / GetValues for that signal receive forged data.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Eclipse Foundation | Eclipse KUKSA - Databroker | >= 0.5.0, <= 0.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-6272?
How severe is CVE-2026-6272?
How do I fix CVE-2026-6272?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62714Integer underflow (wrap or wraparound) in Windows DHCP Serve…6.5
- CVE-2026-62715Integer underflow (wrap or wraparound) in Windows DHCP Serve…6.5
- CVE-2026-62716Integer underflow (wrap or wraparound) in Windows DHCP Serve…6.5
- CVE-2026-62717Heap-based buffer overflow in Windows Message Queuing allows…7.8
- CVE-2026-62718Integer underflow (wrap or wraparound) in Windows DHCP Serve…6.5
- CVE-2026-62719Heap-based buffer overflow in Windows Message Queuing allows…7.8
- CVE-2026-62720Integer underflow (wrap or wraparound) in Windows DHCP Serve…6.5
- CVE-2026-62721Insufficient granularity of access control in User-Mode Powe…7.8
- CVE-2026-62722Heap-based buffer overflow in Windows Bind Filter Driver all…7.8
- CVE-2026-62723Use after free in Windows Telephony Service allows an author…7
- CVE-2026-62724Use after free in Windows Telephony Service allows an author…7
- CVE-2026-62725Use after free in Windows Telephony Service allows an author…7
Are you affected by CVE-2026-6272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
