Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-86464: Eclipse aeriOS Identity Manager exposed admin credentials
CVE-2026-86464 · published 1 month ago
Summary
The development version of Eclipse aeriOS ships with the Identity Manager (Keycloak) and its PostgreSQL database open to the network and using well‑known default usernames and passwords. This allows anyone who can reach those services to log in as an administrator or directly query the database, potentially altering user accounts and security settings. Deployments should be updated to use the new version that generates random passwords and stores all credentials in secure Kubernetes Secrets, and any default accounts should be removed before moving to production.
What to do
- Update eclipse foundation eclipse aerios to version c6efc450baf912385681198b2477c1ba4e93f91a or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| eclipse foundation | eclipse aerios | < c6efc450baf912385681198b2477c1ba4e93f91a |
Original advisory text
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and creden...
In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services.
The Helm chart exposed the Keycloak service and its PostgreSQL backing database through Kubernetes NodePort services by default, while the Docker Compose deployment similarly exposed PostgreSQL on all network interfaces. The deployment included fixed default credentials for the Keycloak administrator and PostgreSQL database user, and the previous Helm chart configuration did not provide adequate secret management for these credentials. In addition, predefined application users with known credentials were provided for development and testing without sufficiently warning operators against their use in production environments.
An attacker able to reach the exposed services could use the published default credentials to obtain administrative access to the Identity Manager or direct access to its database. This could allow unauthorized access to or modification of identity-management data, including users, roles, client credentials, sessions, and cryptographic material, and could enable the creation of privileged identities or tokens accepted by other aeriOS components.
The issue has been addressed by generating a random Keycloak administrator password by default, managing Keycloak and PostgreSQL credentials through Kubernetes Secrets, and restricting PostgreSQL to an internal service in both the Helm chart and Docker Compose deployment. OpenLDAP is also restricted to an internal service. The predefined users intended for development and testing are retained, but the documentation now explicitly warns that their default credentials must not be used in production and that these users should be removed or their credentials changed after installation.
The Helm chart exposed the Keycloak service and its PostgreSQL backing database through Kubernetes NodePort services by default, while the Docker Compose deployment similarly exposed PostgreSQL on all network interfaces. The deployment included fixed default credentials for the Keycloak administrator and PostgreSQL database user, and the previous Helm chart configuration did not provide adequate secret management for these credentials. In addition, predefined application users with known credentials were provided for development and testing without sufficiently warning operators against their use in production environments.
An attacker able to reach the exposed services could use the published default credentials to obtain administrative access to the Identity Manager or direct access to its database. This could allow unauthorized access to or modification of identity-management data, including users, roles, client credentials, sessions, and cryptographic material, and could enable the creation of privileged identities or tokens accepted by other aeriOS components.
The issue has been addressed by generating a random Keycloak administrator password by default, managing Keycloak and PostgreSQL credentials through Kubernetes Secrets, and restricting PostgreSQL to an internal service in both the Helm chart and Docker Compose deployment. OpenLDAP is also restricted to an internal service. The predefined users intended for development and testing are retained, but the documentation now explicitly warns that their default credentials must not be used in production and that these users should be removed or their credentials changed after installation.
References
- https://github.com/eclipse-aerios/idm/pull/1
- https://github.com/eclipse-aerios/idm/commit/364a8cce1cd6be36ba8a400ad41e753052e...
- https://github.com/eclipse-aerios/idm/commit/c6135f3ba1d7351630973b3337850ea40ca...
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/808
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86464... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-86464 Vendor Advisory
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/809
- https://gitlab.eclipse.org/security/vulnerability-reports/-/work_items/829
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-200Information Exposure
CWE-306Missing Authentication for Critical Function
CWE-798Use of Hard-coded Credentials
CWE-1188Initialization of a Resource with an Insecure Default
CWE-1392Use of Default Credentials
Timeline
Published8 Sep 2026
Updated9 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta