securityonline.info 29 Sept 2026, 04:28 UTC

Apache Karaf Flaws Let Low-Privilege Users Seize Admin Access

Apache Karaf Flaws Let Low-Privilege Users Seize Admin Access

APACHE Karaf has fixed four vulnerabilities in version 4.4.12 that could allow low-privilege users, including “viewer” and “manager” accounts, to gain administrator access or execute code in the Karaf Java virtual machine. The flaws affect all versions before 4.4.12. The article says the project’s advisory reports no exploitation in the wild and that no public proof of concept has been confirmed.

CVE-2026-92142, rated important, involves a JMX authorisation gap that allowed authenticated viewers to create, register or remove MBeans. Combined with a standard JDK MBean capable of loading classes from a remote URL, this could lead to remote code execution through JMX, which listens by default on ports 1099 and 44444.

CVE-2026-91012, also important, is a path-traversal flaw in the configuration service that could let managers overwrite protected files, including the user list, and grant themselves administrator privileges.

Two moderate issues could have similar consequences: CVE-2026-91085 allowed viewers to use the insufficiently protected `config:install` command to write downloaded files into Karaf’s `etc` directory, while CVE-2026-91048 left `jdbc:*` commands without an access-control file, allowing users to create data sources from attacker-controlled JDBC URLs. The same gap affects `jms:*` commands.

Administrators should upgrade to Karaf 4.4.12, or 4.5.0 once available. Until then, Apache recommends restricting JMX ports to trusted hosts, avoiding non-admin JMX credentials and tightening command ACLs so unmatched commands fail closed. Non-admin roles should also be audited before and after patching.

View full article

Article by CyberSIXT