Code Injection Vulnerability in Apache Camel K
CVE-2026-80352

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
10 September 2026

What is CVE-2026-80352?

An improper control of code generation vulnerability in Apache Camel K allows an authorized resource author to perform a YAML injection. This can lead to the injection of arbitrary Kubernetes objects, potentially permitting unauthorized resource creation with the privileges of the operator. The affected versions are Apache Camel K ranging from 2.0.0 before 2.9.3 and from 2.10.1 before 2.10.2. Users are advised to upgrade to versions 2.9.3, 2.10.2, or 2.11.0 to mitigate this issue.

Affected Version(s)

Apache Camel K 2.0.0 < 2.9.3

Apache Camel K 2.10.1 < 2.10.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.