Eval Injection Vulnerability in Apache Camel K by Apache
CVE-2026-80351

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 September 2026

What is CVE-2026-80351?

An eval injection vulnerability exists within Apache Camel K, specifically in the improper handling of directives in dynamically evaluated Maven configurations. This flaw allows tenant-controlled repository content to influence the execution of code within operator pods, potentially permitting the execution of arbitrary code with elevated privileges. Versions affected include 2.0.0 through 2.9.2 and 2.10.1 prior to 2.10.2. Users should upgrade to versions 2.9.3, 2.10.2, or 2.11.0 to mitigate this risk.

Affected Version(s)

Apache Camel K 2.0.0 < 2.9.3

Apache Camel K 2.10.1 < 2.10.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.