Command Security Flaw in Apache Karaf Shell SSH Affects User Roles
CVE-2026-91085

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-91085?

A flaw in the Apache Karaf shell and SSH command security mechanism allows authenticated users, even with only a viewer role, to execute the config:install command without appropriate restrictions. This is due to a failure in the access control list (ACL) configuration, which permits unmatched commands, thereby enabling potential unauthorized actions. The vulnerability arises because the karaf.secured.command.compulsory.roles setting is commented out by default, and the config:install command is left without a specific ACL entry. This oversight could allow malicious users to overwrite critical security files within the ${karaf.etc} directory, exposing sensitive data and configurations.

Affected Version(s)

Apache Karaf 0 < 4.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rin Ray <rindilray@gmail.com>
.