Relative Path Traversal Vulnerability in Apache Camel Azure Storage Datalake Component
CVE-2026-60093
Key Information:
- Vendor
Apache
- Status
- Vendor
- CVE Published:
- 24 August 2026
Badges
What is CVE-2026-60093?
A relative path traversal vulnerability has been identified in the Apache Camel Azure Storage Datalake component. This issue enables unauthorized access, allowing malicious users to manipulate file paths during file downloads. Specifically, the component fails to properly validate file paths, permitting files to be written outside the designated directories. Without appropriate checks and constraints enforced, attackers can exploit this flaw to overwrite arbitrary files on the local file system, posing a significant risk to data integrity and security. Users are urged to upgrade to versions that remedy this issue or implement restrictive measures to secure their environments.
Affected Version(s)
Apache Camel 4.0.0 < 4.14.9
Apache Camel 4.15.0 < 4.18.4
Apache Camel 4.19.0 < 4.22.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved