TLS Certificate Validation Vulnerability in Eclipse aeriOS Federator Component
CVE-2026-84736

8.3HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84736?

In the development version of Eclipse aeriOS, the Federator component disables TLS certificate validation by default for outbound HTTPS connections. This misconfiguration allows an attacker to intercept network communications, posing a risk of impersonation of external services and the potential exposure of sensitive information such as OAuth client credentials and bearer tokens. The issue has been mitigated in the newer configuration, where TLS certificate validation is enabled by default, ensuring secure communications.

Affected Version(s)

Eclipse aeriOS d730017a4a0e2a31feba6258bd780efbce7e0d5d < 9c63b60becc9873b0195ff9cd6582b69cb12d4f2

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.