Privilege Escalation Vulnerability in Eclipse hawkBit Device Integration
CVE-2026-16454

4.3MEDIUM

Key Information:

Vendor
CVE Published:
21 July 2026

What is CVE-2026-16454?

In versions 1.0.3 and earlier of Eclipse hawkBit, a significant vulnerability has been detected within the Direct Device Integration (DDI) Controller. This flaw enables an authenticated device to attain elevated permissions, allowing it to bypass predefined restrictions and access unauthorized firmware artifacts assigned to its tenant. The vulnerability is rooted in inadequate object-level authorization validation, not an authentication bypass, as valid credentials for the respective tenant are still required. This issue has broader implications, as the lack of assignment checks in a related software modules metadata endpoint permits authenticated devices to enumerate available firmware artifacts, potentially leading to targeted exfiltration via the primary download authorization flaw.

Affected Version(s)

eclipse-hawkbit/hawkbit 0 <= 1.0.3

eclipse-hawkbit/hawkbit 1.0.4

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Santosh Kumar Puppala (GitHub: Santoshkumarpuppala, Email: santhoshkumar7794@gmail.com)
.