CVE-2026-80351
Analyzed Analyzed - Analysis Complete

Code Injection in Apache Camel K

Vulnerability report for CVE-2026-80351, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-14

Assigner: Apache Software Foundation

Description

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache camel From 2.0.0 (inc) to 2.9.3 (exc)
apache camel From 2.10.0 (inc) to 2.10.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-95 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an improper neutralization of directives in dynamically evaluated code vulnerability in Apache Camel K. It allows tenant-controlled Maven repository content to influence code execution within the operator pod, potentially enabling arbitrary code execution with the operator's privileges.

Detection Guidance

Detecting this vulnerability requires checking the Apache Camel K version in use. Run: kubectl get pods -n <namespace> -l app=camel-k-operator -o jsonpath='{.items[*].spec.containers[?(@.name=="camel-k-operator")].image}' to identify the version. If the version is between 2.0.0 and 2.9.2 or between 2.10.0 and 2.10.1, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability could allow an attacker with access to tenant-controlled repository content to execute arbitrary code on the system running Apache Camel K with elevated privileges. This could lead to unauthorized access, data breaches, or system compromise.

Compliance Impact

This vulnerability could lead to unauthorized code execution and data access, potentially violating GDPR's data protection requirements or HIPAA's security and privacy rules. Compliance may be impacted if sensitive data is exposed or modified due to exploitation.

Mitigation Strategies

Upgrade Apache Camel K to version 2.9.3, 2.10.2, or 2.11.0 to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80351. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart