Junglewise Threat Intelligence

CVE-2026-85199: Eclipse aeriOS Self-orchestrator path traversal in REST API

CVE-2026-85199 · Severity: info · CVSS 8.6 · Published 2026-09-03

Vendors: Eclipse.

Executive brief

Eclipse aeriOS Self-orchestrator is a container-based service that manages rules and facts for event processing. The REST API lacks authentication and allows an attacker to supply specially crafted identifiers with path traversal sequences (like `../`) to write or delete JSON files anywhere on the filesystem. Since the container runs with root privileges, an attacker can overwrite or delete critical system files, potentially causing complete compromise of the host.

Technical details

This is a path traversal vulnerability (CWE-22) in the REST API endpoint handlers. User-controlled `name` and `id` parameters from HTTP request bodies and query strings are concatenated directly into filesystem paths used with `fs.writeFileSync()` and `fs.unlinkSync()` without validation or sanitization. The vulnerability affects multiple endpoints: `POST /rules`, `PUT /rule`, `DELETE /rule`, and `POST /data`. No JSON schema validates or restricts these strings to prevent path separators. The attack requires no authentication, and the service runs as root with the port exposed on the host network in the published Docker image, allowing unauthenticated remote attackers to read, write, and delete arbitrary files. The issue was fixed in version 1.2.1 by introducing input validation to strip path separator characters before constructing filesystem paths.

Affected products

  • Eclipse aeriOS Self-orchestrator prior to 1.2.1

Timeline

  • 2026-09-03: disclosed: CVE-2026-85199 published on NVD
  • 2026-09-01: patched: Version 1.2.1 released with validation and sanitization of identifiers

References