Command Security Flaw in Apache Karaf Shell SSH Affects User Roles
CVE-2026-91085
Currently unrated
What is CVE-2026-91085?
A flaw in the Apache Karaf shell and SSH command security mechanism allows authenticated users, even with only a viewer role, to execute the config:install command without appropriate restrictions. This is due to a failure in the access control list (ACL) configuration, which permits unmatched commands, thereby enabling potential unauthorized actions. The vulnerability arises because the karaf.secured.command.compulsory.roles setting is commented out by default, and the config:install command is left without a specific ACL entry. This oversight could allow malicious users to overwrite critical security files within the ${karaf.etc} directory, exposing sensitive data and configurations.
Affected Version(s)
Apache Karaf 0 < 4.4.12