CVE-2026-91006
Received Received - Intake

Command Injection in Apache Karaf Instance Management

Vulnerability report for CVE-2026-91006, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Apache Software Foundation

Description

Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation  * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache karaf *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Apache Karaf's instance-management service builds a command line for launching a child Karaf JVM by string concatenation and executes it via /bin/sh (Unix) or cscript (Windows). The javaOpts value is inserted unquoted, allowing shell metacharacters like ; | ` $(...) to execute arbitrary OS commands as the Karaf process user.

Detection Guidance

Check for suspicious command execution patterns in Karaf logs or process activity. Monitor for unexpected child JVM launches with unusual javaOpts values. Review access logs for instance:create, instance:start, instance:restart, instance:change-opts, or InstanceMBean operations.

Impact Analysis

An attacker with access to instance:create, instance:start, instance:restart, instance:change-opts, or InstanceMBean operations could execute arbitrary commands on the system as the Karaf user. This could lead to full system compromise, data theft, or denial of service.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements for protected health information. Compliance may be compromised if systems are not properly secured.

Mitigation Strategies
  • Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to restrict command access.
  • Restrict role assignments for instance:* commands and InstanceMBean via etc/users.properties.
  • Treat javaOpts as untrusted input when passed to instance:create, instance:start, instance:change-opts, or InstanceMBean operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91006. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart