PT-2026-84750 · Eclipse+1 · Aerios+1

CVE-2026-82955

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v4.0

9.0

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Eclipse aeriOS (affected versions not specified)
Description The KrakenD instance within the API Gateway component has the disable jwk security parameter hard-coded to true. This configuration disables TLS certificate verification during the retrieval of the JSON Web Key Set (JWKS), which is used to validate bearer tokens. An attacker capable of intercepting this communication could provide a malicious JWKS to compromise the token validation process.
Recommendations Update the configuration to set the Helm value krakend.config.disableJwkSecurity to false to enable TLS certificate verification.

Exploit

Fix

Improper Certificate Validation

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82955

Affected Products

Kraken
Aerios