CVE-2026-86836

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path when the agent (re)starts, the agent reuses it based only on an existence and/or file-type check, without validating its owner or permissions. A local, unprivileged user with write access to the same base directory (by default under `$TMPDIR/ankaios`, e.g. shared `/tmp`) can pre-create this path hierarchy, including the two Control Interface FIFOs, before the agent starts. The agent then treats the attacker-owned FIFOs as the legitimate Control Interface for the targeted workload. The attacker can complete the Control Interface handshake and issue requests using that workload's configured `controlInterfaceAccess` permissions, allowing impersonation of the workload and, depending on its configured permissions, unauthorized reading and/or modification of the cluster's desired state.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 18:20

Updated : 2026-09-15 09:16


NVD link : CVE-2026-86836

Mitre link : CVE-2026-86836

CVE.ORG link : CVE-2026-86836


JSON object : View

Products Affected

No product.

CWE
CWE-276

Incorrect Default Permissions

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-379

Creation of Temporary File in Directory with Insecure Permissions