CVE-2026-80515 PUBLISHED

Assigner: eclipse
Reserved: 26.08.2026 Published: 03.09.2026 Updated: 03.09.2026

In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/systems (%6D == m) therefore fails the substring check — the filter falls through without authorising — yet is decoded to /serviceregistry/mgmt/systems and dispatched to the management controller. Spring Security's StrictHttpFirewall (active via spring-boot-starter-security in arrowhead-common) only rejects encoded / \ . % ; and null bytes, so percent-encoded ASCII letters pass through. Any authenticated system — regardless of privilege — can reach every management operation, including POST /authentication/mgmt/identities which creates new sysop accounts, yielding full administrative takeover of the local cloud.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
CVSS Score: 8.9

Product Status

Vendor Eclipse Foundation
Product Eclipse Arrowhead
Versions Default: unaffected
  • affected from 5.0.0 to 5.2.1 (incl.)

Credits

  • Eclipse Foundation Security Team finder

References

Problem Types

  • CWE-647 Use of Non-Canonical URL paths for authorization decisions CWE
  • CWE-863 Incorrect Authorization CWE