CVE-2026-91012
Received
Received - Intake
Path Traversal in Apache Karaf Configuration
Vulnerability report for CVE-2026-91012, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-29
Last updated on: 2026-09-29
Assigner: Apache Software Foundation
Description
Description
org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),
which backs the "config" MBean and the config:* shell commands, derives the file
it writes a configuration to from caller-supplied input without checking that
the result stays insideΒ ${karaf.etc}:
* if the submitted property map contains aΒ felix.fileinstall.filenameΒ entry, that value is turned directly into aΒ FileΒ (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;
* otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outsideΒ ${karaf.etc}.Β createFactoryConfiguration()Β has the same issue via the factory PID/alias.
Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg:Β "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties,Β etc/*.acl.*.cfg,Β etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.
ConfigMBeanImpl.install()Β and theΒ config:installΒ shell command already guarded the equivalent risk on their own code path with aΒ finalname.contains("..")Β string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied toΒ ConfigRepositoryImpl.update()Β /Β createFactoryConfiguration()Β at all.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | karaf | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |