CVE-2026-66906
Received Received - Intake

Relative Path Traversal in Apache Camel Azure Storage Blob Component

Vulnerability report for CVE-2026-66906, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: Apache Software Foundation

Description

Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download an Azure Storage blob to the local filesystem through its downloadBlobToFile operation, writing into the directory named by the fileDir endpoint option, which is documented as usable from both the producer and the consumer. BlobOperations.downloadBlobToFile built the local target by joining fileDir with the remote blob name exactly as the Azure SDK reported it (new File(fileDir, client.getBlobName())) and passed the result straight to the SDK download call, with no lexical normalization and no check that the resolved location stayed inside fileDir. The blob name is not route-controlled data: the consumer enumerates the container in BlobConsumer.createBatchExchangesFromContainer, which lists blobs and creates one exchange per entry from BlobItem.getName() verbatim, applying no name filtering by default. A blob name containing parent-directory segments therefore resolved to a location outside the configured fileDir, letting anyone able to influence the names present in the consumed container cause Camel to create or overwrite a file at a location of their choosing, with the privileges of the Camel process. Depending on what the process can write to, overwriting a file outside the download directory can escalate beyond the loss of integrity of that file. Azure Storage blob containers use a flat namespace in which the blob name is an opaque key, so a name carrying such segments is stored and listed as given. The fileDir option is an ordinary common-group configuration parameter and carries no security marker, so nothing signalled to users that its value was not being enforced as a containment boundary. Camel's other file-download consumers - camel-file, camel-ftp, camel-smb, camel-mina-sftp and camel-azure-files - already constrained their local downloads to the configured directory using a path-segment boundary check; the camel-azure-storage-blob download path was not covered by that work. Users are recommended to upgrade to version 4.22.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.9. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.4. For deployments that cannot upgrade immediately, constrain the names the consumer will act on using the regex endpoint option, which is applied to each listed blob name as a full-string match, so that only simple single-segment names are accepted and any name carrying a path separator or a parent-directory segment is filtered out before an exchange is created; the prefix option can additionally narrow the listing server-side, noting that when both are set regex takes priority and prefix is ignored. Alternatively, avoid the downloadBlobToFile operation on untrusted containers and write the payload from the route under a file name the route itself controls, rather than one taken from the remote listing. As defence in depth, treat the blob names in any externally writable container as untrusted input and do not derive local filesystem paths from them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
apache camel 4.0.0
apache camel 4.14.9
apache camel 4.15.0
apache camel 4.18.4
apache camel 4.19.0
apache camel 4.22.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a relative path traversal vulnerability in Apache Camel's Azure Storage Blob component. It allows attackers to write files outside the intended download directory by using blob names containing directory traversal sequences like '../'. The vulnerability exists because the component combines the configured download directory with the blob name without proper validation.

Detection Guidance

Check Apache Camel version with: mvn dependency:tree | grep camel-azure-storage-blob. If version is between 4.0.0-4.14.8, 4.15.0-4.18.3, or 4.19.0-4.21.9, the system is vulnerable. Inspect logs for downloadBlobToFile operations targeting unexpected paths.

Impact Analysis

An attacker with write access to an Azure Storage container could create or overwrite files on the local filesystem where the Camel process runs. This could lead to loss of data integrity, unauthorized file access, or even privilege escalation depending on what the Camel process can write to.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized file creation or overwrites outside intended directories. If exploited, it may lead to unauthorized access to sensitive data, violating confidentiality requirements under these regulations. The ability to write files outside the configured directory could result in data breaches or unauthorized modifications, which are critical compliance violations.

Mitigation Strategies

Upgrade to Apache Camel 4.22.0, 4.18.4, or 4.14.9. If immediate upgrade is not possible, add regex endpoint option to filter blob names like '^[^/]+$' or avoid downloadBlobToFile on untrusted containers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66906. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart