In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.
Weaknesses CWE-1023
CWE-863
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2026-09-17T10:34:44.255Z

Reserved: 2026-09-16T14:10:16.252Z

Link: CVE-2026-92611

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T11:17:03.210

Modified: 2026-09-17T11:17:03.210

Link: CVE-2026-92611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses