CVE-2026-92611: Eclipse Foundation Eclipse Ankaios
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.
Affected products
- Eclipse Foundation Eclipse Ankaios: from 0.6.0, before 1.0.4 (fixed in 1.0.4)
Published 2026-09-17. Last modified 2026-09-18.