Description
In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state.
Published: 2026-09-14
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Workload impersonation and unauthorized state modification
Action: Apply Patch
AI Analysis

Impact

The vulnerability causes the Eclipse Ankaios agent to create predictable FIFO control interfaces for workloads inside a shared base directory; it accepts a pre‑existing FIFO if one already exists without validating owner or permissions. A local unprivileged user who can write to this directory may pre‑create the FIFO hierarchy, making the agent believe the attacker’s FIFO is the legitimate workload control interface. During the normal handshake the attacker can then issue arbitrary requests, effectively impersonating the targeted workload and, according to that workload’s configured permissions, reading or altering the cluster’s desired state.

Affected Systems

Eclipse Foundation’s Eclipse Ankaios is affected, specifically all versions from 0.1.0 through 1.0.2 inclusive. These versions deploy the agent and FIFO handling code as described.

Risk and Exploitability

The CVSS score of 8.4 indicates a high severity flaw, though the EPSS score is 0.00086, indicating a very low exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. It is exploitable by a local, unprivileged user who has write access to the shared base directory (typically $TMPDIR/ankaios), enabling the creation of the FIFO path. Once the agent starts, it will bind to the attacker-owned FIFOs, leading to potential unauthorized configuration changes rather than remote code execution. The attack does not cross host boundaries and relies on local directory permissions to be misconfigured.

Generated by OpenCVE AI on September 20, 2026 at 23:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Eclipse Ankaios to version 1.0.3 or later, where FIFO creation is secured against pre‑existing paths.
  • Configure the agent to use a non‑shared temporary directory or ensure the base directory is writable only by the agent user.
  • Immediately delete any pre‑existing FIFO files or directories in the base path before restarting the agent.

Generated by OpenCVE AI on September 20, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Title Eclipse Ankaios FIFO Pre-Creation Allows Workload Impersonation

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse ankaios
Vendors & Products Eclipse
Eclipse ankaios

Tue, 15 Sep 2026 08:30:00 +0000


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state.
Weaknesses CWE-276
CWE-367
CWE-379
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-15T08:18:26.215Z

Reserved: 2026-09-08T14:40:05.969Z

Link: CVE-2026-86836

cve-icon Vulnrichment

Updated: 2026-09-14T18:00:21.730Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T18:20:20.193

Modified: 2026-09-16T20:38:33.883

Link: CVE-2026-86836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions

  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition

  • CWE-379

    Creation of Temporary File in Directory with Insecure Permissions