// Eclipse Ankaios / case study

Authorization bypass in workload control rules

A flaw in the agent-side Control Interface authorizer allowed a scoped workload to use an empty field mask and access or modify cluster state outside its authorized subtree.

Published | CVE-2026-84173 | High 8.3Disclosure-safe summary
Trust-boundary path
01Restricted workload
02Control Interface authorization
03Cluster state

Project and affected component

The agent-side Control Interface authorizer and its evaluation of field masks against configured allow rules.

Security boundary

A workload granted access to a limited state subtree should not be able to read or modify cluster state outside that scope.

Vulnerability class

Incorrect authorization resulting in unauthorized disclosure or modification of cluster state.

Root cause

Multi-segment allow rules beginning with a wildcard were evaluated incorrectly when a request supplied an empty field mask. The empty mask could be treated as matching the scoped rule even though it selected broader state than the rule was intended to authorize. A rule consisting only of a wildcard has intentionally unrestricted semantics. Multi-segment wildcard rules should not inherit that behavior.

Validation method

Source review traced the authorization decision from the incoming request to field-mask evaluation. Controlled reproductions confirmed the behavior across affected versions, negative controls separated intended wildcard behavior from the bypass, and the maintainer fix was retested against the same cases.

Practical impact

A workload operating with scoped Control Interface permissions could read complete cluster state or modify workloads and configuration outside its authorized subtree.

Disclosure status

The Eclipse Foundation assigned CVE-2026-84173 and GHSA-rp6v-x3q5-cp2g. The issue was fixed in Eclipse Ankaios v1.0.2. The public CVE record credits Ievgen Bondarenko as the reporter.

Remediation

Treat a standalone wildcard and a multi-segment wildcard rule as different authorization cases. Reject empty field masks unless unrestricted state access was explicitly granted, and upgrade affected deployments to the fixed release.

Public references