CVE-2026-86464

9.9

Eclipse Foundation · Eclipse aeriOS

The Eclipse aeriOS Identity Manager deployment contains insecure default configurations and hard-coded credentials, allowing unauthenticated remote attackers to gain administrative access.

Executive summary

A critical vulnerability in the development version of Eclipse aeriOS exposes administrative interfaces and databases to the network, permitting full unauthorized control over identity management services.

Vulnerability

The vulnerability involves the exposure of Keycloak and PostgreSQL services via insecure network configurations and the use of hard-coded default credentials. This allows an unauthenticated attacker to bypass security controls and gain administrative access to the Identity Manager system.

Business impact

Successful exploitation grants an attacker complete control over the Identity Manager, leading to the potential compromise of all managed user accounts, roles, and session tokens. With a CVSS score of 9.9, this vulnerability poses a catastrophic risk to organizational security, as it allows for the exfiltration of sensitive cryptographic material and the creation of rogue privileged identities.

Remediation

Immediate Action: Upgrade to commit c6efc450baf912385681198b2477c1ba4e93f91a or later, and ensure that all default credentials are rotated immediately upon deployment.

Proactive Monitoring: Review Kubernetes and network access logs for unauthorized connections to Keycloak or database ports, and audit all identity management configurations for unexpected modifications.

Compensating Controls: Restrict network access to the Identity Manager deployment via firewall rules or Kubernetes network policies to ensure services are not exposed to untrusted interfaces.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity of this flaw, administrators must prioritize the update to the remediated version immediately. If the software is currently in a production environment, ensure that all default credentials are purged and that services are isolated from public network access until the update is applied.

More Eclipse Foundation CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Eclipse Foundation Security Team, per the CVE Program record.