PT-2026-91285 · Eclipse Foundation · Eclipse Ankaios

CVE-2026-86836

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions Eclipse Ankaios versions 0.1.0 through 1.0.2
Description The agent creates workload files and Control Interface named pipes (FIFOs) using a predictable path based on the agent name and a hash of the workload's runtime configuration. When the agent starts or restarts, it reuses existing directories or FIFOs at that path without validating ownership or permissions. A local, unprivileged user with write access to the base directory (typically $TMPDIR/ankaios) can pre-create this path hierarchy and the Control Interface FIFOs. This allows the attacker to impersonate the workload by completing the Control Interface handshake and issuing requests using the controlInterfaceAccess permissions, potentially leading to unauthorized reading or modification of the cluster's desired state.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Time Of Check To Time Of Use

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86836

Affected Products

Eclipse Ankaios