CVE-2026-82958 affects Eclipse Ditto versions 1.3.0 through 3.9.6, where the ImplicitThingCreationMessageMapper improperly escapes placeholder values from message headers, allowing attackers to inject JSON structure and override access-control policies on newly created digital twins. Exploitation requires the non-default mapper configuration, an attacker-controllable header in the template, and policy-creation permissions.