Access Control Flaw in Eclipse Ankaios Affecting Log Rule Evaluation
CVE-2026-92611

4.8MEDIUM

Key Information:

Vendor
CVE Published:
17 September 2026

What is CVE-2026-92611?

In Eclipse Ankaios versions prior to 1.0.4, the LogRule::matches method within the agent control-interface authorizer can prematurely halt at the first wildcard match in a rule. This behavior may permit the bypass of subsequent deny LogRule entries, potentially exposing log data to unauthorized users. The oversight raises critical security concerns as it allows access to sensitive logs from different workloads, necessitating immediate attention from users to implement the latest secure versions.

Affected Version(s)

Eclipse Ankaios 0.6.0 < 1.0.4

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Eclipse Foundation Security Team
.