Remote Code Execution Risk in Apache Karaf JMX Remote Interface
CVE-2026-92142

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-92142?

A significant vulnerability in Apache Karaf arises from improper role-based access control (RBAC) on the JMX MBeanServer. While operations like 'invoke,' 'getAttribute,' and 'setAttribute' are protected by the KarafMBeanServerGuard, MBean lifecycle methods 'createMBean,' 'registerMBean,' and 'unregisterMBean' are not. This oversight means any authenticated user, including those with minimal 'viewer' roles, can create arbitrary MBeans and execute potentially harmful remote code by exploiting the JMX endpoint. Attackers can leverage standard JDK MBeans to fetch and instantiate classes from malicious URLs without proper authorization checks, thereby compromising the integrity of the Karaf server. Immediate action is advised by upgrading to the latest versions or restricting network access to the JMX interface.

Affected Version(s)

Apache Karaf 0 < 4.4.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

MopMonk-AI <mopmonk-ai@tophant.com>
.