CVE-2026-91085
Received Received - Intake

Command Injection in Apache Karaf

Vulnerability report for CVE-2026-91085, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule matches the command, fails open: ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety valve for this, karaf.secured.command.compulsory.roles, ships commented out in etc/system.properties, so an unmatched command is allowed for any authenticated user. The shipped org.apache.karaf.command.acl.config ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. It restricts delete to admin, restricts edit/property-*/update on the jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* PIDs to admin, and allows manager for everything else, but config:install was simply unmatched, and therefore allowed for any authenticated user, including one holding only the viewer role. config:install <url> <finalname> fetches url and writes it into ${karaf.etc} as finalname. It calls PathUtils.checkWithin() to block .. traversal outside karaf.etc, but that folder holds every security-relevant file Karaf ships: users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* files, including the very ACL file that (mis)governs this command. With -o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL. Because felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix FileInstall also watches and reloads any .cfg file dropped there, closing the loop without requiring a restart. By contrast, bundle:install, feature:install and kar:install are all admin-only in their own ACLs, and config:delete is admin in this same ACL, config:install was the outlier. MitigationAdd install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the file is absent), and/or set karaf.secured.command.compulsory.roles=admin in etc/system.properties (and restart) to make unmatched commands fail closed by default.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache karaf to 4.4.12 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-91085 is a vulnerability in Apache Karaf where the config:install command lacks proper access control. This allows any authenticated user, even with minimal privileges like 'viewer', to execute the command and fetch files from arbitrary URLs into the Karaf etc directory. This directory contains critical security files such as users.properties and ACL configurations.

Detection Guidance

Check Apache Karaf logs for unauthorized config:install commands. Inspect etc/org.apache.karaf.command.acl.config.cfg for missing install = admin entry. Monitor etc directory for unexpected file modifications or new .cfg files.

Impact Analysis

An attacker could exploit this to overwrite sensitive files in the Karaf etc directory, including ACL configurations, using the --override flag. This could lead to privilege escalation, allowing the attacker to gain admin-level access. Felix FileInstall automatically reloads modified files, enabling the attack without requiring a restart.

Compliance Impact

This vulnerability could lead to unauthorized access and modification of sensitive data, violating confidentiality and integrity requirements in GDPR and HIPAA. Unrestricted file overwrites in critical directories may result in non-compliance with data protection and security standards.

Mitigation Strategies

Add install = admin to etc/org.apache.karaf.command.acl.config.cfg. Alternatively, set karaf.secured.command.compulsory.roles=admin in etc/system.properties and restart Karaf. Remove unnecessary write permissions in etc directory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91085. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart