Insecure Default Configurations in Eclipse aeriOS Identity Manager by Eclipse
CVE-2026-86464
What is CVE-2026-86464?
The current development version of Eclipse aeriOS includes severe vulnerabilities due to insecure default configurations and fixed credentials that compromise sensitive services. The default deployment method exposes crucial services like Keycloak and PostgreSQL through Kubernetes NodePort and all network interfaces respectively. This setup allows an attacker to leverage known default credentials for administrative access, enabling unauthorized modifications of critical identity management data. Newly implemented security measures, including random credential generation and better secret management, seek to mitigate these risks while maintaining awareness that predefined users meant for testing should not be utilized in production environments.
Affected Version(s)
Eclipse aeriOS 459fa98e95b1865d01b8d14d6cce5908ba2b18ba
