PT-2026-61989 · Eclipse · Hawkbit

CVE-2026-16454

·

Published

2026-07-21

·

Updated

2026-07-21

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Eclipse hawkBit versions prior to 1.0.3
Description A privilege escalation issue exists in the Direct Device Integration (DDI) Controller due to a flaw in object-level authorization validation. This allows an authenticated device with valid tenant credentials to bypass restrictions and download any firmware artifact within the same tenant, rather than being limited to specifically assigned updates. Additionally, the listing software modules artifacts metadata endpoint fails to enforce assignment checks, allowing authenticated devices to enumerate available firmware artifacts and facilitate targeted exfiltration.
Recommendations Update to a version newer than 1.0.3.

Exploit

Fix

Improper Access Control

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16454
GHSA-92R3-P8C2-3FPX

Affected Products

Hawkbit