CVE-2026-80515

In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/systems (%6D == m) therefore fails the substring check — the filter falls through without authorising — yet is decoded to /serviceregistry/mgmt/systems and dispatched to the management controller. Spring Security's StrictHttpFirewall (active via spring-boot-starter-security in arrowhead-common) only rejects encoded / \ . % ; and null bytes, so percent-encoded ASCII letters pass through. Any authenticated system — regardless of privilege — can reach every management operation, including POST /authentication/mgmt/identities which creates new sysop accounts, yielding full administrative takeover of the local cloud.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-03 14:17

Updated : 2026-09-03 16:41


NVD link : CVE-2026-80515

Mitre link : CVE-2026-80515

CVE.ORG link : CVE-2026-80515


JSON object : View

Products Affected

No product.

CWE
CWE-647

Use of Non-Canonical URL Paths for Authorization Decisions

CWE-863

Incorrect Authorization