Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-91012— Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation

Quick assessment

Affected
Apache Software Foundation Apache Karaf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

方法(该方法支撑 “config” MBean 及 Shell 命令)在将配置写入文件时,直接根据调用者提供的输入推导目标文件路径,而未检查最终路径是否仍位于 目录内: 如果提交的属性映射中包含 条目,该值会被直接转换为 对象(通过 方法),因此可以指向 Karaf 进程具有写入权限的任意绝对路径; 否则,配置 PID 会原样拼接进目标文件名中( 方法: ),因此如果 PID 中包含 片段,解析后的路径将超出 目录。 方法通过工厂 PID/别名也存在相同的问题。 在 Karaf 默认提供的命令/JMX ACL( 中

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91012

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
Source: CVE Program / CVE List V5
Vulnerability Description
org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that the result stays inside ${karaf.etc}: * if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to; * otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias. Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container. ConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains("..") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Karaf 0 ~ 4.4.12 -

II. Public POCs for CVE-2026-91012

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91012

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-91012 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-29 · 18 CVEs total

CVE-2026-102496 Apache XMLSchema: Denial of service through deeply nested schema structures
CVE-2026-91048 Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege esc
CVE-2026-91085 Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
CVE-2026-92142 Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
CVE-2026-81914 Apache Airflow Google provider: Google Drive query injection via unescaped file and folder
CVE-2026-81862 Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credenti
CVE-2026-81930 Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer toke
CVE-2026-86843 Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-
CVE-2026-102495 Apache XMLSchema: Denial of service through unbounded recursion when resolving schema impo
CVE-2026-71897 Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and ba
CVE-2026-102497 Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker
CVE-2026-66083 Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasourc
CVE-2026-82804 Apache DolphinScheduler: Command Injection in the Alert Script Plugin
CVE-2026-81569 Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized
CVE-2026-78214 Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
CVE-2026-71899 Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to
CVE-2026-71898 Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute

IV. Related Vulnerabilities

V. Comments for CVE-2026-91012

No comments yet


Leave a comment