目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-84173

一分钟漏洞结论

影响对象
Eclipse Foundation Eclipse Ankaios
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Eclipse Ankaios 版本 v0.5.1 至 v1.0.1 中,代理端的控制接口(Control Interface)授权器对以通配符开头的多段允许规则(allow rules)进行评估时存在错误。当一个经过身份验证的工作负载(workload)受此类规则限制时,它可以提交 或 ,其中字段掩码(field mask)为空。该请求可能被错误地授权为匹配受限规则,从而允许该工作负载读取完整的集群状态,或在其授权子树之外替换状态。这可能导致其他工作负载或集群配置发生未授权的披露或修改。只有仅由 组成的规则才

CVSS 8.3 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-84173 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by such a rule can submit a CompleteStateRequest or UpdateStateRequest with an empty field mask. The request may then be incorrectly authorized as matching the scoped rule, allowing the workload to read the complete cluster state or replace state outside its authorized subtree. This may result in unauthorized disclosure or modification of other workloads and cluster configuration. Only a rule consisting solely of * is intended to authorize an empty mask. Mitigation: Until an update containing the fix is installed, avoid multi-segment Control Interface allow-rule filter masks that begin with a wildcard, such as *.workloads.some_workload. Replace them with explicit paths such as desiredState.workloads.some_workload, where applicable. A filter mask consisting solely of * has different, intentionally unrestricted semantics and should only be used when full-state access is intended.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
来源: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Eclipse Foundation Eclipse Ankaios 0.5.1 ~ 1.0.1 -

二、漏洞 CVE-2026-84173 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-84173 的情报信息

登录查看更多情报信息。

CVE-2026-84173 其他参考 (4)

IV. Related Vulnerabilities

V. Comments for CVE-2026-84173

暂无评论


发表评论