CVE-2026-9561: CWE-348: Use of Less Trusted Source in Eclipse Foundation Eclipse Kura
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections — such as fail2ban — by spoofing the logged IP address to a non-routable value, allowing a brute-force attack to proceed undetected, or to cause a denial of service against a third party by injecting a victim's IP address and triggering a ban on that address.
AI Analysis
Technical Summary
CVE-2026-9561 affects Eclipse Kura versions 5.0.0 through 5.6.1. The vulnerability arises because the Web Console and REST API components use the X-Forwarded-For HTTP header as the primary source for client IP addresses when initializing audit context. Additionally, Jetty's ForwardedRequestCustomizer is installed unconditionally on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. This enables unauthenticated remote attackers to spoof IP addresses in audit logs, bypassing IP-based brute-force protections such as fail2ban or causing denial of service by injecting victim IPs to trigger bans.
Potential Impact
An attacker can bypass IP-based brute-force protections by spoofing the X-Forwarded-For header, causing audit logs to record a non-routable or attacker-chosen IP address instead of the true client IP. This allows brute-force attacks to proceed undetected. Additionally, attackers can cause denial of service against third parties by injecting their IP addresses into logs, triggering automated bans on those victim IPs.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should consider disabling or restricting the use of the X-Forwarded-For header as a trusted source for client IP addresses in audit logs, or implement additional validation to ensure the authenticity of client IP information. Monitoring and adjusting IP-based blocking tools to account for this behavior may also help mitigate risk.
CVE-2026-9561: CWE-348: Use of Less Trusted Source in Eclipse Foundation Eclipse Kura
Description
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections — such as fail2ban — by spoofing the logged IP address to a non-routable value, allowing a brute-force attack to proceed undetected, or to cause a denial of service against a third party by injecting a victim's IP address and triggering a ban on that address.
CVSS v4.0
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-9561 affects Eclipse Kura versions 5.0.0 through 5.6.1. The vulnerability arises because the Web Console and REST API components use the X-Forwarded-For HTTP header as the primary source for client IP addresses when initializing audit context. Additionally, Jetty's ForwardedRequestCustomizer is installed unconditionally on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. This enables unauthenticated remote attackers to spoof IP addresses in audit logs, bypassing IP-based brute-force protections such as fail2ban or causing denial of service by injecting victim IPs to trigger bans.
Potential Impact
An attacker can bypass IP-based brute-force protections by spoofing the X-Forwarded-For header, causing audit logs to record a non-routable or attacker-chosen IP address instead of the true client IP. This allows brute-force attacks to proceed undetected. Additionally, attackers can cause denial of service against third parties by injecting their IP addresses into logs, triggering automated bans on those victim IPs.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, organizations should consider disabling or restricting the use of the X-Forwarded-For header as a trusted source for client IP addresses in audit logs, or implement additional validation to ensure the authenticity of client IP information. Monitoring and adjusting IP-based blocking tools to account for this behavior may also help mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- eclipse
- Date Reserved
- 2026-05-26T10:32:07.026Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a55f44d68715ace431bbf45
Added to database: 07/14/2026, 08:33:17 UTC
Last enriched: 07/14/2026, 08:47:30 UTC
Last updated: 08/24/2026, 11:40:11 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.