Relative Path Traversal Vulnerability in Apache Camel Azure Storage Datalake Component
CVE-2026-60093
What is CVE-2026-60093?
A relative path traversal vulnerability has been identified in the Apache Camel Azure Storage Datalake component. This issue enables unauthorized access, allowing malicious users to manipulate file paths during file downloads. Specifically, the component fails to properly validate file paths, permitting files to be written outside the designated directories. Without appropriate checks and constraints enforced, attackers can exploit this flaw to overwrite arbitrary files on the local file system, posing a significant risk to data integrity and security. Users are urged to upgrade to versions that remedy this issue or implement restrictive measures to secure their environments.
Affected Version(s)
Apache Camel 4.0.0 < 4.14.9
Apache Camel 4.15.0 < 4.18.4
Apache Camel 4.19.0 < 4.22.0