CVE-2026-92611: Eclipse Ankaios vulnerability
In Eclipse Ankaios versions 0.6.0 to before 1.0.4, LogRule::matches in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny LogRule entries to be skipped and allow unauthorized access to another workload's logs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Eclipse Ankaiosto a version that resolves this vulnerability.Fixed in 1.0.4
Event History
Frequently Asked Questions
Which deployments are exposed?
Eclipse Ankaios deployments running versions 0.6.0 through versions before 1.0.4 are affected where agent control-interface authorization uses LogRule entries with wildcard patterns followed by later entries that are intended to deny log access.
What access could an attacker gain?
The flaw can allow unauthorized access to another workload's logs when a deny LogRule is skipped because matching stops at an earlier wildcard pattern.
What is the remediation?
Upgrade Eclipse Ankaios to version 1.0.4 or later. The issue is fixed in the v1.0.4 release.