CVE-2026-80354
Received
Received - Intake
Authorization Bypass in Apache Camel K via User-Controlled Key
Vulnerability report for CVE-2026-80354, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-10
Last updated on: 2026-09-10
Assigner: Apache Software Foundation
Description
Description
Authorization bypass through User-Controlled key vulnerability in Apache Camel K.
An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components.
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.
Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | camel_k | From 2.0.0 (inc) to 2.9.3 (exc) |
| apache | camel_k | From 2.10.0 (inc) to 2.10.2 (exc) |
| apache | camel_k | 2.9.3 |
| apache | camel_k | 2.10.2 |
| apache | camel_k | 2.11.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |