PT-2026-91285 · Eclipse Foundation · Eclipse Ankaios
CVE-2026-86836
·
Published
2026-09-14
·
Updated
2026-09-15
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
Eclipse Ankaios versions 0.1.0 through 1.0.2
Description
The agent creates workload files and Control Interface named pipes (FIFOs) using a predictable path based on the agent name and a hash of the workload's runtime configuration. When the agent starts or restarts, it reuses existing directories or FIFOs at that path without validating ownership or permissions. A local, unprivileged user with write access to the base directory (typically
$TMPDIR/ankaios) can pre-create this path hierarchy and the Control Interface FIFOs. This allows the attacker to impersonate the workload by completing the Control Interface handshake and issuing requests using the controlInterfaceAccess permissions, potentially leading to unauthorized reading or modification of the cluster's desired state.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Time Of Check To Time Of Use
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eclipse Ankaios