In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures its HTTP transport to skip TLS certificate verification.




As a result, an attacker able to intercept network communications between the Federator and external services could impersonate those services and intercept sensitive information transmitted over HTTPS, including OAuth client credentials and bearer tokens.




The issue has been addressed by enabling TLS certificate validation by default. The TLS_CERTIFICATE_VALIDATION environment variable is now set to true in the default configuration provided by the Helm chart and Docker Compose deployment.

Project Subscriptions

Vendors Products
Eclipse Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 03 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title Federator Component Disables TLS Certificate Validation by Default, Allowing Man‑in‑the‑Middle Attacks

Thu, 03 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Eclipse
Eclipse aerios
Vendors & Products Eclipse
Eclipse aerios

Thu, 03 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Federator Component Disables TLS Certificate Validation by Default, Allowing Man‑in‑the‑Middle Attacks

Thu, 03 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures its HTTP transport to skip TLS certificate verification. As a result, an attacker able to intercept network communications between the Federator and external services could impersonate those services and intercept sensitive information transmitted over HTTPS, including OAuth client credentials and bearer tokens. The issue has been addressed by enabling TLS certificate validation by default. The TLS_CERTIFICATE_VALIDATION environment variable is now set to true in the default configuration provided by the Helm chart and Docker Compose deployment.
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-03T17:38:14.998Z

Reserved: 2026-09-02T08:31:41.292Z

Link: CVE-2026-84736

cve-icon Vulnrichment

Updated: 2026-09-03T17:38:12.183Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:25.427

Modified: 2026-09-03T18:17:28.243

Link: CVE-2026-84736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T19:45:05Z

Weaknesses