Executive brief
Eclipse Arrowhead is an open-source framework for building secure Industrial IoT (IIoT) systems. A flaw in its authorization filter allows authenticated users to bypass management endpoint protections by submitting specially crafted HTTP requests with percent-encoded path segments, enabling attackers to create administrator accounts and take complete control of a local cloud deployment.
Technical details
The vulnerability is a classic authorization bypass caused by a mismatch between URL decoding at different layers (CWE-647). The ManagementServiceFilter checks authorization by calling request.getRequestURL().toString().contains("/mgmt/"), but Tomcat returns this un-decoded while Spring MVC's DispatcherServlet routes on the decoded path. An attacker can request /serviceregistry/%6Dgmt/systems (%6D is the percent-encoded form of 'm'), which fails the substring check and bypasses the filter, yet is decoded to /serviceregistry/mgmt/systems and routed to the protected management controller. Spring Security's StrictHttpFirewall only blocks a limited set of encoded characters, allowing percent-encoded ASCII letters through. Any authenticated system—regardless of privilege level—can reach all management operations, including POST /authentication/mgmt/identities to create sysop accounts. Under the default "declared" authentication policy, this requires only an HTTP Authorization header with arbitrary content.
Affected products
- Eclipse Arrowhead 5.0.0 to 5.2.1
Timeline
- 2026-09-03: disclosed