Privilege Escalation in Apache Karaf JDBC Shell Command
CVE-2026-91048
Currently unrated
What is CVE-2026-91048?
A security vulnerability exists in the JDBC shell command scope of Apache Karaf due to the absence of an access control list (ACL) configuration for the command. The command guard (SecuredSessionFactoryImpl) allows any authenticated shell session to execute all JDBC commands without proper authorization. This flaw enables a user with only viewer role privileges to create JDBC data sources with unvalidated user-controlled URLs, ultimately leading to the execution of arbitrary code. This situation creates a critical chain of privilege escalation that bypasses existing administrative safeguards, posing significant security risks to affected systems.
Affected Version(s)
Apache Karaf 0 < 4.4.12