Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-91048— Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create

Quick assessment

Affected
Apache Software Foundation Apache Karaf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

随附的 JDBC shell 命令作用域未包含 ACL 规则文件。Karaf 的命令守卫机制( )将未匹配到任何 ACL 规则的命令视为允许执行。因此,任何已认证的 shell 会话(即使仅持有 角色)都可以执行所有 命令。 命令会将完全由攻击者控制的 JDBC URL 存储到 工厂配置中,且未进行任何验证。 会响应式地将该配置转换为一个活跃的数据源(DataSource)。由于某些 JDBC 驱动程序会在连接时根据 URL 参数执行代码或 SQL(例如 H2 的 参数),因此持有 权限的 shell 用户可以实现

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91048

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
Source: CVE Program / CVE List V5
Vulnerability Description
The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an "admin misconfiguration". The same applies to jms:* shell commands.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Karaf 0 ~ 4.4.12 -

II. Public POCs for CVE-2026-91048

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91048

请登录查看更多情报信息。

Mailing List Discussions for CVE-2026-91048 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-29 · 19 CVEs total

CVE-2026-102496 Apache XMLSchema: Denial of service through deeply nested schema structures
CVE-2026-91012 Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalatio
CVE-2026-91085 Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
CVE-2026-92142 Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
CVE-2026-81914 Apache Airflow Google provider: Google Drive query injection via unescaped file and folder
CVE-2026-81862 Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credenti
CVE-2026-81930 Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer toke
CVE-2026-86843 Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-
CVE-2026-102495 Apache XMLSchema: Denial of service through unbounded recursion when resolving schema impo
CVE-2026-97395 Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO req
CVE-2026-102497 Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker
CVE-2026-66083 Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasourc
CVE-2026-82804 Apache DolphinScheduler: Command Injection in the Alert Script Plugin
CVE-2026-81569 Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized
CVE-2026-78214 Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
CVE-2026-71899 Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to
CVE-2026-71898 Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute
CVE-2026-71897 Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and ba

IV. Related Vulnerabilities

V. Comments for CVE-2026-91048

No comments yet


Leave a comment