Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86836

Quick assessment

Affected
Eclipse Foundation Eclipse Ankaios
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Eclipse Ankaios 0.1.0 至 1.0.2 版本中,agent 会根据 agent 名称以及工作负载运行时配置的哈希值,在一个可预测的路径下创建用于工作负载的文件和名为“Control Interface” 的命名管道(FIFO)。当 agent(重新)启动时,如果该路径下已经存在目录或 FIFO,agent 仅基于“是否存在”和/或“文件类型”检查来复用它,而未验证其所有者或权限。本地非特权用户如果对该基础目录(默认为 ,例如共享的 )具有写权限,就可以在 agent 启动前预创建该路径层级,

CVSS 8.4 · High

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts

Affected Version Matrix 1

VendorProduct Version RangeStatus
Eclipse Foundation Eclipse Ankaios 0.1.0≤ 1.0.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86836

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
在具有不安全权限的目录中创建临时文件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Eclipse Foundation Eclipse Ankaios 0.1.0 ~ 1.0.2 -

II. Public POCs for CVE-2026-86836

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86836

登录查看更多情报信息。

Vendor Pages for CVE-2026-86836 (1)

Same Patch Batch · Eclipse Foundation · 2026-09-14 · 4 CVEs total

CVE-2026-88819 6.3 MEDIUM Siglet历史版本刷新令牌处理器DID证明缺失
CVE-2026-89321 4.3 MEDIUM CVE-2026-89321
CVE-2026-78299 Eclipse CDT 6.0-6.7 路径遍历漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-86836

No comments yet


Leave a comment