Access Control Flaw in Eclipse Ankaios Affecting Log Rule Evaluation
CVE-2026-92611
4.8MEDIUM
What is CVE-2026-92611?
In Eclipse Ankaios versions prior to 1.0.4, the LogRule::matches method within the agent control-interface authorizer can prematurely halt at the first wildcard match in a rule. This behavior may permit the bypass of subsequent deny LogRule entries, potentially exposing log data to unauthorized users. The oversight raises critical security concerns as it allows access to sensitive logs from different workloads, necessitating immediate attention from users to implement the latest secure versions.
Affected Version(s)
Eclipse Ankaios 0.6.0 < 1.0.4
