Insecure Default Configurations in Eclipse aeriOS Identity Manager by Eclipse
CVE-2026-86464

9.9CRITICAL

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-86464?

The current development version of Eclipse aeriOS includes severe vulnerabilities due to insecure default configurations and fixed credentials that compromise sensitive services. The default deployment method exposes crucial services like Keycloak and PostgreSQL through Kubernetes NodePort and all network interfaces respectively. This setup allows an attacker to leverage known default credentials for administrative access, enabling unauthorized modifications of critical identity management data. Newly implemented security measures, including random credential generation and better secret management, seek to mitigate these risks while maintaining awareness that predefined users meant for testing should not be utilized in production environments.

Affected Version(s)

Eclipse aeriOS 459fa98e95b1865d01b8d14d6cce5908ba2b18ba

References

CVSS V4

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.