← Vulnerability feed

Vulnerability record · CVE-2026-9561 · published 14 July 2026

CVE-2026-9561: Eclipse kura insufficient verification of data authenticity vulnerability

Eclipse · Kura

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections — such as fail2ban — by spoofing the logged IP address to a non-routable value, allowing a brute-force attack to proceed undetected, or to cause a denial of service against a third party by injecting a victim's IP address and triggering a ban on that address.

8.8 CVSS 4.0 High EPSS 0.28% · top 81.7% CWE-345 · Insufficient verification of data authenticityCWE-348 · CWE-348
8.8CVSS 4.0 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
18 Aug 2026Last modified by NVD

Description

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections — such as fail2ban — by spoofing the logged IP address to a non-routable value, allowing a brute-force attack to proceed undetected, or to cause a denial of service against a third party by injecting a victim's IP address and triggering a ban on that address.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://gitlab.eclipse.org/security/cve-assignment/-/work_items/117 ExploitIssue TrackingPatchThird Party Advisory

Track CVE-2026-9561 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-7649Eclipse kura improper authentication vulnerabilityThe network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be con…EPSS 1.6%7.5CVE-2024-3046Eclipse kura vulnerabilityIn Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated …EPSS 0.58%7.5CVE-2019-10244Eclipse kura xml external entity (xxe) vulnerabilityIn Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service …EPSS 1.8%5.3CVE-2019-10242Eclipse kura path traversal vulnerabilityIn Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get…EPSS 2.0%5.3CVE-2019-10243Eclipse kura information exposure vulnerabilityIn Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to …EPSS 1.3%7.8CVE-2023-38831WinRAR ZIP archive spoofing leads to arbitrary code executionWinRAR before 6.23 mishandles ZIP archives that contain a benign file and a folder with the same name, causing the folder's contents to be processed …KEVEPSS 100%analysed9.8CVE-2022-26871Trend Micro Apex Central unauthenticated arbitrary file uploadTrend Micro Apex Central (and Apex One) contains an arbitrary file upload flaw caused by insufficient verification of data authenticity (CWE-345). An…KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2026-9561), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.