Executive brief
Eclipse aeriOS Federator is a component that manages secure communications between IoT services. By default, it disables TLS certificate validation for outbound HTTPS connections, allowing attackers on the network to impersonate external services and steal sensitive credentials such as OAuth client secrets and authentication tokens. Organizations using this component in production are exposed to credential theft and service impersonation.
Technical details
The vulnerability is an improper certificate validation issue (CWE-295) in the Federator's HTTP transport configuration. The root cause is in config/config.go and main.go: when the TLS_CERTIFICATE_VALIDATION environment variable is unset or set to false, the component configures http.DefaultTransport with InsecureSkipVerify: true, disabling all certificate verification. This affects all outbound HTTPS calls, including Keycloak OAuth authentication (which transmits client credentials), peer-federator notifications (which transmit bearer tokens), and aerios-shim token fetches. An attacker positioned on the network path can perform man-in-the-middle attacks to intercept and steal these credentials. The vulnerability has been patched by enabling TLS certificate validation by default in the Helm chart and Docker Compose configuration files.
Affected products
- Eclipse aeriOS Federator development versions (no official release published; internal versioning 1.0.1–1.1.0)
Timeline
- 2026-09-03: disclosed: CVE-2026-84736 published
- patched: TLS_CERTIFICATE_VALIDATION enabled by default in Helm chart and Docker Compose configuration