Junglewise Threat Intelligence

CVE-2026-80515: Eclipse Arrowhead management authorization bypass via percent-encoded paths

CVE-2026-80515 · Severity: info · CVSS 9.1 · Published 2026-09-03

Vendors: Eclipse.

Executive brief

Eclipse Arrowhead is an open-source framework for building secure Industrial IoT (IIoT) systems. A flaw in its authorization filter allows authenticated users to bypass management endpoint protections by submitting specially crafted HTTP requests with percent-encoded path segments, enabling attackers to create administrator accounts and take complete control of a local cloud deployment.

Technical details

The vulnerability is a classic authorization bypass caused by a mismatch between URL decoding at different layers (CWE-647). The ManagementServiceFilter checks authorization by calling request.getRequestURL().toString().contains("/mgmt/"), but Tomcat returns this un-decoded while Spring MVC's DispatcherServlet routes on the decoded path. An attacker can request /serviceregistry/%6Dgmt/systems (%6D is the percent-encoded form of 'm'), which fails the substring check and bypasses the filter, yet is decoded to /serviceregistry/mgmt/systems and routed to the protected management controller. Spring Security's StrictHttpFirewall only blocks a limited set of encoded characters, allowing percent-encoded ASCII letters through. Any authenticated system—regardless of privilege level—can reach all management operations, including POST /authentication/mgmt/identities to create sysop accounts. Under the default "declared" authentication policy, this requires only an HTTP Authorization header with arbitrary content.

Affected products

  • Eclipse Arrowhead 5.0.0 to 5.2.1

Timeline

  • 2026-09-03: disclosed

References

Related threats