Description
In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.
Published: 2026-09-17
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Log Access
Action: Apply Patch
AI Analysis

Impact

A flaw in the LogRule::matches function causes the evaluation to halt at the first wildcard pattern within a rule, preventing subsequent deny entries from being processed. As a result, an attacker can bypass log access controls and read logs from other workloads that should be restricted, compromising confidentiality.

Affected Systems

The vulnerability affects Eclipse Ankaios versions 0.6.0 up to, but not including, 1.0.4. The product is maintained by the Eclipse Foundation.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate impact. The EPSS score is unavailable, and the issue is not listed in the CISA KEV catalog. While the exact attack vector is not explicitly documented, it is inferred that exploitation requires access to the agent control‑interface and possibly elevation of privilege within the same environment. The vulnerability is therefore likely exploitable in an internal or local context rather than over the public network.

Generated by OpenCVE AI on September 18, 2026 at 06:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Eclipse Ankaios to version 1.0.4 or later to remove the wildcard evaluation bug.
  • If immediate update is not possible, reconfigure LogRule deny entries to avoid using wildcard patterns that can terminate evaluation before later deny rules are considered.
  • Review and enforce strict access controls on log endpoints, ensuring that only authorized users can query logs from specific workloads.

Generated by OpenCVE AI on September 18, 2026 at 06:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse ankaios
Vendors & Products Eclipse
Eclipse ankaios

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.
Weaknesses CWE-1023
CWE-863
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-17T12:09:56.395Z

Reserved: 2026-09-16T14:10:16.252Z

Link: CVE-2026-92611

cve-icon Vulnrichment

Updated: 2026-09-17T12:09:52.545Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T11:17:03.210

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-92611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:00:06Z

Weaknesses
  • CWE-1023

    Incomplete Comparison with Missing Factors

  • CWE-863

    Incorrect Authorization