{"id":"CVE-2026-86836","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86836","summary":null,"details":"In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state.","published":"2026-09-14T17:44:56.384Z","modified":"2026-09-16T03:47:58.143203963Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/eclipse-ankaios/ankaios/pull/799","label":"eclipse-ankaios/ankaios#799"},"references":[{"type":"WEB","url":"https://github.com/eclipse-ankaios/ankaios/releases/tag/v1.0.3"},{"type":"WEB","url":"https://gitlab.eclipse.org/security/cve-assignment/-/work_items/280"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86836.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86836"},{"type":"FIX","url":"https://github.com/eclipse-ankaios/ankaios/pull/799"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:47:58.143203963Z"}}