CVE-2026-9561

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections — such as fail2ban — by spoofing the logged IP address to a non-routable value, allowing a brute-force attack to proceed undetected, or to cause a denial of service against a third party by injecting a victim's IP address and triggering a ban on that address.
References
Link Resource
https://gitlab.eclipse.org/security/cve-assignment/-/work_items/117 Exploit Issue Tracking Patch Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:kura:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-14 09:16

Updated : 2026-08-18 17:54


NVD link : CVE-2026-9561

Mitre link : CVE-2026-9561

CVE.ORG link : CVE-2026-9561


JSON object : View

Products Affected

eclipse

  • kura
CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-348

Use of Less Trusted Source

CWE-807

Reliance on Untrusted Inputs in a Security Decision