Executive brief
Eclipse Arrowhead is an IoT middleware framework used to build autonomous systems and federated cloud infrastructures. When the MQTT API is enabled with certificate authentication (the default policy), the CertificateMqttFilter component accepts any self-signed X.509 certificate presented in the MQTT message payload without verifying its signature or validating against any trust store. An attacker who can publish to the MQTT broker can forge a certificate with system operator identity and gain complete management access to the Arrowhead system, enabling them to register/delete systems, services, and users.
Technical details
The vulnerability is a certificate validation bypass (CWE-295, CWE-287, CWE-290) in the CertificateMqttFilter class. The vulnerable component parses an X.509 certificate embedded in the MQTT message payload's authentication field using CertificateFactory.generateCertificate(), but performs no cryptographic signature verification or issuer chain validation. Authorization is reduced to two string comparisons on attacker-controlled data: DN-qualifier must equal "sy" or "op", and the cloud-name portion of the CN must match the server's (both public values). An attacker who can publish to the MQTT broker can mint a self-signed certificate with CN=Sysop.<cloud>.<org>.arrowhead.eu and dnQualifier=op, send it in the authentication field, and be authenticated as a system operator with full management API access. The HTTP CertificateFilter is not affected because it validates certificates through Tomcat's mTLS handshake against a configured trust store. A patch is expected to introduce proper certificate chain validation.
Affected products
- Eclipse Arrowhead 5.0.0 to 5.2.1
Timeline
- 2026-09-03: disclosed: CVE-2026-82180 published