CVE-2026-92611

Published Sep 17, 2026 Modified Sep 17, 2026 CWE-863 CWE-1023

Description

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.

Is your site exposed to CVE-2026-92611?

Run a free security scan — no signup, results in seconds.

Weakness Type (CWE)

CWE-863 Incorrect Authorization
CWE-1023 CWE-1023

References

Frequently Asked Questions

What is CVE-2026-92611? +
In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entries to be skipped and allow unauthorized access to another workload's logs.
How do I check if I'm vulnerable to CVE-2026-92611? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2026-92611 — free, no signup required.