Eclipse Ankaios wildcard authorization bypass in Control Interface
Eclipse Ankaios versions v0.5.1 through v1.0.1 have an authorization bypass vulnerability where multi-segment allow rules with leading wildcards incorrectly authorize empty field masks, allowing authenticated workloads to access or modify restricted cluster state.
Disclosed 7 September 2026 · Record updated 13 September 2026
Impact
Authenticated workloads could read complete cluster state or replace state outside their authorized scope, potentially causing unauthorized disclosure or modification of other workloads and cluster configuration.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-287g-w4gp-cqxr
