CVE-2026-86836: CWE-379 in Eclipse Foundation Eclipse Ankaios
Eclipse Ankaios versions 0.1.0 through 1.0.2 contain a vulnerability where the agent reuses existing workload files and Control Interface FIFOs without validating ownership or permissions. This allows a local unprivileged user with write access to the base directory to pre-create these FIFOs and impersonate the workload, potentially reading or modifying the cluster's desired state based on configured permissions. The vulnerability is rated high severity with a CVSS score of 8.4.
AI Analysis
Technical Summary
In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If these files or FIFOs already exist when the agent starts or restarts, the agent reuses them based solely on existence and file-type checks, without validating ownership or permissions. A local, unprivileged user with write access to the base directory (defaulting to $TMPDIR/ankaios, such as a shared /tmp) can pre-create this path hierarchy and FIFOs before the agent starts. The agent then treats these attacker-owned FIFOs as legitimate Control Interfaces, allowing the attacker to complete the Control Interface handshake and issue requests with the workload's configured controlInterfaceAccess permissions. This can lead to impersonation of the workload and unauthorized reading or modification of the cluster's desired state depending on permissions.
Potential Impact
A local unprivileged attacker with write access to the agent's base directory can impersonate a workload by pre-creating Control Interface FIFOs. This allows the attacker to issue requests with the workload's controlInterfaceAccess permissions, potentially leading to unauthorized reading or modification of the cluster's desired state. The vulnerability compromises workload integrity and confidentiality within the cluster environment.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict write access to the agent's base directory (default $TMPDIR/ankaios) to trusted users only to prevent pre-creation of FIFOs by unprivileged users.
CVE-2026-86836: CWE-379 in Eclipse Foundation Eclipse Ankaios
Description
Eclipse Ankaios versions 0.1.0 through 1.0.2 contain a vulnerability where the agent reuses existing workload files and Control Interface FIFOs without validating ownership or permissions. This allows a local unprivileged user with write access to the base directory to pre-create these FIFOs and impersonate the workload, potentially reading or modifying the cluster's desired state based on configured permissions. The vulnerability is rated high severity with a CVSS score of 8.4.
CVSS v4.0
Score 8.4high
Affected software
Eclipse Foundation
Eclipse Ankaios
pkg:github/eclipse-foundation/ankaiosRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If these files or FIFOs already exist when the agent starts or restarts, the agent reuses them based solely on existence and file-type checks, without validating ownership or permissions. A local, unprivileged user with write access to the base directory (defaulting to $TMPDIR/ankaios, such as a shared /tmp) can pre-create this path hierarchy and FIFOs before the agent starts. The agent then treats these attacker-owned FIFOs as legitimate Control Interfaces, allowing the attacker to complete the Control Interface handshake and issue requests with the workload's configured controlInterfaceAccess permissions. This can lead to impersonation of the workload and unauthorized reading or modification of the cluster's desired state depending on permissions.
Potential Impact
A local unprivileged attacker with write access to the agent's base directory can impersonate a workload by pre-creating Control Interface FIFOs. This allows the attacker to issue requests with the workload's controlInterfaceAccess permissions, potentially leading to unauthorized reading or modification of the cluster's desired state. The vulnerability compromises workload integrity and confidentiality within the cluster environment.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict write access to the agent's base directory (default $TMPDIR/ankaios) to trusted users only to prevent pre-creation of FIFOs by unprivileged users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-09-08T14:40:05.969Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa83dad55bf5e2cf57193ea
Added to database: 09/14/2026, 18:32:13 UTC
Last enriched: 09/14/2026, 18:46:29 UTC
Last updated: 09/14/2026, 18:46:29 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.