Threats Tagged 'cve-2026-86464'
View all threats tagged with 'cve-2026-86464'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-86464'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-86464: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Eclipse Foundation Eclipse aeriOSCVE-2026-86464 0 CVE-2026-86464 is a critical vulnerability in the development version of Eclipse aeriOS Identity Manager. It involves insecure default configurations and credentials that expose Keycloak and PostgreSQL services through Kubernetes NodePort and Docker Compose deployments. Default fixed credentials allow unauthorized actors to gain administrative access to identity management data and potentially create privileged identities. The issue has been addressed by randomizing passwords, using Kubernetes Secrets for credential management, restricting service exposure, and warning against using predefined test users in production. Join the discussion | CVE Database V5 | 09/08/2026, 19:43:28 UTC Added: 09/08/2026, 19:52:45 UTC |
Showing 1 to 1 of 1 result