File Write Vulnerability in Apache Karaf Configuration Management
CVE-2026-91012

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-91012?

The Apache Karaf configuration management system has a vulnerability in its ConfigRepositoryImpl class that allows an attacker with manager privileges to write arbitrary files. The update method processes caller-supplied input without proper validation, enabling a user to manipulate the configuration file path. This could allow the attacker to create or alter sensitive files, such as those related to user and role management, granting themselves elevated permissions or administrative access to the system. The existing safeguards for other commands do not apply in this case, making it critical for users to ensure their environments are secure and up to date to mitigate potential exploitation.

Affected Version(s)

Apache Karaf 0 < 4.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

n0mi1k <nomilksec@gmail.com>
.