PT-2026-84750 · Eclipse+1 · Aerios+1
CVE-2026-82955
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v4.0
9.0
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Eclipse aeriOS (affected versions not specified)
Description
The KrakenD instance within the API Gateway component has the
disable jwk security parameter hard-coded to true. This configuration disables TLS certificate verification during the retrieval of the JSON Web Key Set (JWKS), which is used to validate bearer tokens. An attacker capable of intercepting this communication could provide a malicious JWKS to compromise the token validation process.Recommendations
Update the configuration to set the Helm value
krakend.config.disableJwkSecurity to false to enable TLS certificate verification.Exploit
Fix
Improper Certificate Validation
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kraken
Aerios