File Write Vulnerability in Apache Karaf Configuration Management
CVE-2026-91012
Currently unrated
What is CVE-2026-91012?
The Apache Karaf configuration management system has a vulnerability in its ConfigRepositoryImpl class that allows an attacker with manager privileges to write arbitrary files. The update method processes caller-supplied input without proper validation, enabling a user to manipulate the configuration file path. This could allow the attacker to create or alter sensitive files, such as those related to user and role management, granting themselves elevated permissions or administrative access to the system. The existing safeguards for other commands do not apply in this case, making it critical for users to ensure their environments are secure and up to date to mitigate potential exploitation.
Affected Version(s)
Apache Karaf 0 < 4.4.12