Junglewise Threat Intelligence

CVE-2026-86464: Eclipse aeriOS Identity Manager insecure default credentials and exposure

CVE-2026-86464 · Severity: info · CVSS 0 · Published 2026-09-08

Vendors: Eclipse.

Executive brief

Eclipse aeriOS is an identity management platform. The development version shipped with hardcoded default credentials and exposed critical services (Keycloak admin interface and database) to the network by default. An attacker with network access could use these published credentials to gain administrative control over user identities, roles, and authentication tokens, potentially compromising access to other systems that rely on this identity service.

Technical details

The vulnerability stems from insecure default configurations in the Helm chart and Docker Compose deployment for Eclipse aeriOS Identity Manager. The Keycloak service and its PostgreSQL database were exposed via Kubernetes NodePort services and on all network interfaces respectively, with fixed hardcoded default credentials for both services and predefined development/test users with known passwords. An unauthenticated attacker on the network could reach these exposed services, authenticate using the published default credentials, and gain administrative access to the identity management system, allowing unauthorized access to or modification of users, roles, client credentials, sessions, and cryptographic material. The fix involves generating random Keycloak administrator passwords, using Kubernetes Secrets for credential management, and restricting PostgreSQL and OpenLDAP to internal services only.

Affected products

  • Eclipse aeriOS development version (pre-release)

Timeline

  • 2026-09-08: disclosed

Related threats