PT-2026-94224 · Eclipse · Ankaios
CVE-2026-92611
·
Published
2026-09-17
·
Updated
2026-09-17
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Eclipse Ankaios versions 0.6.0 through 1.0.3
Description
In the agent control-interface authorizer, the
LogRule::matches() function stops processing at the first wildcard pattern encountered within a single rule instead of evaluating subsequent entries. This behavior can lead to the omission of deny LogRule entries, potentially granting unauthorized access to logs belonging to other workloads.Recommendations
Update Eclipse Ankaios to version 1.0.4 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ankaios