In Eclipse Ankaios versions 0.6.0 to before 1.0.4, LogRule::matches in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny LogRule entries to be skipped and allow unauthorized access to another workload's logs.
{
"cna_assigner": "eclipse",
"cwe_ids": [
"CWE-1023",
"CWE-863"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92611.json"
}