Impact
The vulnerability causes the Eclipse Ankaios agent to create predictable FIFO control interfaces for workloads inside a shared base directory; it accepts a pre‑existing FIFO if one already exists without validating owner or permissions. A local unprivileged user who can write to this directory may pre‑create the FIFO hierarchy, making the agent believe the attacker’s FIFO is the legitimate workload control interface. During the normal handshake the attacker can then issue arbitrary requests, effectively impersonating the targeted workload and, according to that workload’s configured permissions, reading or altering the cluster’s desired state.
Affected Systems
Eclipse Foundation’s Eclipse Ankaios is affected, specifically all versions from 0.1.0 through 1.0.2 inclusive. These versions deploy the agent and FIFO handling code as described.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity flaw, though the EPSS score is 0.00086, indicating a very low exploitation probability. The vulnerability is not yet listed in the CISA KEV catalog. It is exploitable by a local, unprivileged user who has write access to the shared base directory (typically $TMPDIR/ankaios), enabling the creation of the FIFO path. Once the agent starts, it will bind to the attacker-owned FIFOs, leading to potential unauthorized configuration changes rather than remote code execution. The attack does not cross host boundaries and relies on local directory permissions to be misconfigured.
OpenCVE Enrichment