Junglewise Threat Intelligence

CVE-2026-16454: Eclipse hawkBit privilege escalation in DDI Controller

CVE-2026-16454 · Severity: medium · CVSS 4.3 · Published 2026-07-21

Vendors: Eclipse Foundation.

Executive brief

Eclipse hawkBit is a framework used to manage software and firmware updates for IoT devices. A security flaw in the Direct Device Integration (DDI) component allows an authenticated device to download firmware updates that were not specifically assigned to it. While an attacker must already have valid device credentials, they could use this vulnerability to access and exfiltrate any firmware artifacts belonging to the same organization or 'tenant.'

Technical details

A privilege escalation vulnerability (CWE-284 / CWE-862) exists in the Direct Device Integration (DDI) Controller of Eclipse hawkBit. The flaw is rooted in improper object-level authorization validation within the `hawkbit-ddi-resource` component. While authentication is required, the system fails to verify if a specific firmware artifact is explicitly assigned to the requesting device before allowing a download. An attacker with valid device credentials can enumerate available firmware via a metadata endpoint and subsequently download any artifact within their tenant's scope. This issue is resolved in version 1.0.4 by enforcing assignment-based verification on all download requests.

Affected products

  • Eclipse Foundation hawkbit-ddi-resource <= 1.0.3

Timeline

  • 2026-06-26: advisory: GitHub security advisory published
  • 2026-07-21: disclosed: CVE published to NVD

References