Relative Path Traversal Vulnerability in Apache Camel Azure Storage Datalake Component
CVE-2026-60093

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
24 August 2026

What is CVE-2026-60093?

A relative path traversal vulnerability has been identified in the Apache Camel Azure Storage Datalake component. This issue enables unauthorized access, allowing malicious users to manipulate file paths during file downloads. Specifically, the component fails to properly validate file paths, permitting files to be written outside the designated directories. Without appropriate checks and constraints enforced, attackers can exploit this flaw to overwrite arbitrary files on the local file system, posing a significant risk to data integrity and security. Users are urged to upgrade to versions that remedy this issue or implement restrictive measures to secure their environments.

Affected Version(s)

Apache Camel 4.0.0 < 4.14.9

Apache Camel 4.15.0 < 4.18.4

Apache Camel 4.19.0 < 4.22.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hiep Nguyen
n0mi1k
Andrea Cosentino
.