CVE-2026-9561

Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections — such as fail2ban — by spoofing the logged IP address to a non-routable value, allowing a brute-force attack to proceed undetected, or to cause a denial of service against a third party by injecting a victim's IP address and triggering a ban on that address.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Jul 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 09:16

Updated : 2026-07-14 16:38


NVD link : CVE-2026-9561

Mitre link : CVE-2026-9561

CVE.ORG link : CVE-2026-9561


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity

CWE-348

Use of Less Trusted Source

CWE-807

Reliance on Untrusted Inputs in a Security Decision