PT-2026-61989 · Eclipse · Hawkbit
CVE-2026-16454
·
Published
2026-07-21
·
Updated
2026-07-21
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Eclipse hawkBit versions prior to 1.0.3
Description
A privilege escalation issue exists in the Direct Device Integration (DDI) Controller due to a flaw in object-level authorization validation. This allows an authenticated device with valid tenant credentials to bypass restrictions and download any firmware artifact within the same tenant, rather than being limited to specifically assigned updates. Additionally, the listing software modules artifacts metadata endpoint fails to enforce assignment checks, allowing authenticated devices to enumerate available firmware artifacts and facilitate targeted exfiltration.
Recommendations
Update to a version newer than 1.0.3.
Exploit
Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hawkbit