SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80515

HIGH · CVSS 8.9 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Eclipse Arrowhead versions 5.0.0 to 5.2.1 are vulnerable due to a flaw in the management-authorization gate that allows unauthenticated users to bypass security checks on REST endpoints. This vulnerability enables attackers to exploit encoded URLs to access sensitive management operations, potentially leading to full administrative control over the system. Organizations using affected versions should prioritize immediate patching to mitigate the risk of unauthorized access and administrative takeover.

CVE
CVE-2026-80515
Severity
HIGH
CVSS
8.9
EPSS
0.29%

Original NVD Description

In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whether to apply its check by calling request.getRequestURL().toString().contains("/mgmt/"). Tomcat returns getRequestURL() un-decoded, while Spring MVC's DispatcherServlet routes on the decoded path. Requesting /serviceregistry/%6Dgmt/systems (%6D == m) therefore fails the substring check — the filter falls through without authorising — yet is decoded to /serviceregistry/mgmt/systems and dispatched to the management controller. Spring Security's StrictHttpFirewall (active via spring-boot-starter-security in arrowhead-common) only rejects encoded / \ . % ; and null bytes, so percent-encoded ASCII letters pass through. Any authenticated system — regardless of privilege — can reach every management operation, including POST /authentication/mgmt/identities which creates new sysop accounts, yielding full administrative takeover of the local cloud.