Privilege Escalation in Apache Karaf JDBC Shell Command
CVE-2026-91048

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-91048?

A security vulnerability exists in the JDBC shell command scope of Apache Karaf due to the absence of an access control list (ACL) configuration for the command. The command guard (SecuredSessionFactoryImpl) allows any authenticated shell session to execute all JDBC commands without proper authorization. This flaw enables a user with only viewer role privileges to create JDBC data sources with unvalidated user-controlled URLs, ultimately leading to the execution of arbitrary code. This situation creates a critical chain of privilege escalation that bypasses existing administrative safeguards, posing significant security risks to affected systems.

Affected Version(s)

Apache Karaf 0 < 4.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MopMonk-AI <mopmonk-ai@tophant.com>
.