Path Traversal Vulnerability in Eclipse aeriOS Self-orchestrator
CVE-2026-85199

8.8HIGH

Key Information:

Vendor
CVE Published:
3 September 2026

What is CVE-2026-85199?

The aeriOS Self-orchestrator from Eclipse is subjected to a serious security vulnerability due to improper validation of user-controlled identifiers in its REST API. This flaw permits an unauthenticated remote attacker to execute path traversal attacks, allowing them to manipulate filesystem paths. By sending manipulated identifiers, attackers can potentially write or delete important JSON files outside the designated application directories. The exploitability is exacerbated by the lack of authentication on the API and the elevated privileges of the container in the default deployment configuration. To mitigate this risk, version 1.2.1 introduces comprehensive validation and sanitization of identifiers, preventing malicious path manipulation.

Affected Version(s)

Eclipse aeriOS 63993c83fb71bb2c4981731b4980ff93c72a6750

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.