๐Ÿ” CVE Alert

CVE-2026-92611

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.

CWE CWE-863 CWE-1023
Vendor eclipse foundation
Product eclipse ankaios
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for eclipse foundation eclipse ankaios

Be the first to know when new unknown vulnerabilities affecting eclipse foundation eclipse ankaios are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Eclipse Foundation / Eclipse Ankaios
0.6.0 < 1.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/eclipse-ankaios/ankaios/security/advisories/GHSA-qcqx-hx4v-25rg gitlab.eclipse.org: https://gitlab.eclipse.org/security/cve-assignment/-/work_items/308 github.com: https://github.com/eclipse-ankaios/ankaios/releases/tag/v1.0.4 github.com: https://github.com/eclipse-ankaios/ankaios/pull/805

Credits

Eclipse Foundation Security Team