Description
In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/systems (%6D == m) therefore fails the substring check — the filter falls through without authorising — yet is decoded to /serviceregistry/mgmt/systems and dispatched to the management controller. Spring Security's StrictHttpFirewall (active via spring-boot-starter-security in arrowhead-common) only rejects encoded / \ . % ; and null bytes, so percent-encoded ASCII letters pass through. Any authenticated system — regardless of privilege — can reach every management operation, including POST /authentication/mgmt/identities which creates new sysop accounts, yielding full administrative takeover of the local cloud.
Published: 2026-09-03
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The flaw is in the management‑authorization gate that uses a substring check on the raw, undecoded request URL. An attacker can encode the path segment %6Dgmt to bypass the check, allowing any authenticated system to access management endpoints and create new system operator accounts, resulting in full administrative control of the local cloud.

Affected Systems

Eclipse Arrowhead versions 5.0.0 to 5.2.1 are affected. The vulnerability impacts the Arrowhead management REST API exposed under /…/mgmt/…, including services like the service registry and authentication controller. These require the Arrowhead-common module and spring‑boot‑starter‑security.

Risk and Exploitability

The CVSS score of 8.9 indicates a high‑severity flaw. Although an EPSS score is not available, the lack of mitigation in the default configuration and the ability to leverage any authenticated account make exploitation likely. The vulnerability is not listed in CISA KEV, but its exploit path simply requires an HTTP request with a percent‑encoded segment, which any user with network access to the system can craft.

Generated by OpenCVE AI on September 3, 2026 at 14:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a patched release of Eclipse Arrowhead (e.g., 5.2.2 or later) that corrects the URL validation logic.
  • Restrict access to the /…/mgmt/… REST endpoints to privileged users or network segments until a patch is applied.
  • Implement additional input validation or an HTTP firewall rule that blocks percent‑encoded path segments to prevent bypass of the authorization check.

Generated by OpenCVE AI on September 3, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse arrowhead
Vendors & Products Eclipse
Eclipse arrowhead

Thu, 03 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Title Encoded Path Exploit in Eclipse Arrowhead Management Gateway Grants Admin Privileges

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/systems (%6D == m) therefore fails the substring check — the filter falls through without authorising — yet is decoded to /serviceregistry/mgmt/systems and dispatched to the management controller. Spring Security's StrictHttpFirewall (active via spring-boot-starter-security in arrowhead-common) only rejects encoded / \ . % ; and null bytes, so percent-encoded ASCII letters pass through. Any authenticated system — regardless of privilege — can reach every management operation, including POST /authentication/mgmt/identities which creates new sysop accounts, yielding full administrative takeover of the local cloud.
Weaknesses CWE-647
CWE-863
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Eclipse Arrowhead
cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-03T13:49:45.714Z

Reserved: 2026-08-26T14:21:43.506Z

Link: CVE-2026-80515

cve-icon Vulnrichment

Updated: 2026-09-03T13:49:42.470Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T14:17:01.830

Modified: 2026-09-03T16:41:09.297

Link: CVE-2026-80515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:32:54Z

Weaknesses
  • CWE-647

    Use of Non-Canonical URL Paths for Authorization Decisions

  • CWE-863

    Incorrect Authorization