CVE-2026-86671
Received Received - Intake

Arbitrary File Read and SSRF in Eclipse Che

Vulnerability report for CVE-2026-86671, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Eclipse Foundation

Description

In Eclipse Che versions 7.29.0 and later, the GET `/api/scm/resolve` and `POST /api/factory/resolver` endpoints pass an attacker-controlled URL to `URLFetcher.fetch()`, which calls `new URL(url).openConnection()` with no scheme or host allow-list and returns the response body to the caller. Any authenticated Che user can read arbitrary local files via the file:// scheme (including the pod's Kubernetes service-account token at `file:///var/run/secrets/kubernetes.io/serviceaccount/token`), reach internal HTTP services and cloud instance metadata endpoints (169.254.169.254), and have their stored SCM personal access token attached as an `Authorization` header to a host of their choosing. The same credential-forwarding behavior also fires when a victim opens a workspace from a malicious devfile whose `parent.uri` points to an attacker-controlled server, enabling exfiltration of the victim's SCM PAT without direct API access. No fix is available.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Eclipse Foundation Eclipse Che 7.29.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Eclipse Che versions 7.29.0 and later allows authenticated users to exploit endpoints that fetch URLs without proper validation. Attackers can use the file:// scheme to read local files, including Kubernetes service account tokens, or access internal services and cloud metadata endpoints. Credentials may also be forwarded to attacker-controlled hosts.

Impact Analysis

If you use Eclipse Che 7.29.0 or later, an attacker with access could steal sensitive files, Kubernetes tokens, or internal service data. They might also exfiltrate stored SCM personal access tokens or access cloud metadata, leading to potential data breaches or unauthorized cloud resource usage.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Exposure of personal or health data may result in regulatory penalties and loss of compliance certifications.

Mitigation Strategies

Disable the affected endpoints GET /api/scm/resolve and POST /api/factory/resolver in Eclipse Che. Restrict network access to these endpoints to trusted users only. Monitor for unusual file:// or internal HTTP requests originating from Che workspaces.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86671. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart