CVE-2026-84736

Source
https://cve.org/CVERecord?id=CVE-2026-84736
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84736.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84736
Published
2026-09-03T16:10:32.871Z
Modified
2026-09-05T03:48:27.148195339Z
Severity
  • 8.3 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLSCERTIFICATEVALIDATION environment variable is unset or set to false, the component configures its HTTP transport to skip TLS certificate verification.

As a result, an attacker able to intercept network communications between the Federator and external services could impersonate those services and intercept sensitive information transmitted over HTTPS, including OAuth client credentials and bearer tokens.

The issue has been addressed by enabling TLS certificate validation by default. The TLSCERTIFICATEVALIDATION environment variable is now set to true in the default configuration provided by the Helm chart and Docker Compose deployment.

Database specific
{
    "cwe_ids": [
        "CWE-295"
    ],
    "cna_assigner": "eclipse",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84736.json"
}
References

Affected packages

Git / github.com/eclipse-aerios/federator

Affected ranges

Type
GIT
Repo
https://github.com/eclipse-aerios/federator
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84736.json"