CVE-2026-45760
published 2026-05-21CVE-2026-45760: (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K…
PriorityP352high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.33%
25.0th percentile
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace.
This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_camel_k | >= 2.0.0 < 2.8.1 | 2.8.1 |
| apache_software_foundation | apache_camel_k | >= 2.10.0 < 2.10.1 | 2.10.1 |
| apache_software_foundation | apache_camel_k | >= 2.9.0 < 2.9.2 | 2.9.2 |
| github.com | apache_camel-k_v2 | >= 0 < 2.8.1 | 2.8.1 |
| github.com | apache_camel-k_v2 | >= 2.10.0 < 2.10.1 | 2.10.1 |
| github.com | apache_camel-k_v2 | >= 2.9.0 < 2.9.2 | 2.9.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q8ch-jx67-q52x: (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K
ghsa_unreviewed·2026-05-21
CVE-2026-45760 CWE-610 GHSA-q8ch-jx67-q52x: (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace.
This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue.
GHSA
Apache Camel K: Kubernetes namespace authorized users can create a Build resource
ghsa·2026-05-21
CVE-2026-45760 [HIGH] CWE-610 Apache Camel K: Kubernetes namespace authorized users can create a Build resource
Apache Camel K: Kubernetes namespace authorized users can create a Build resource
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace.
This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue.
VulDB
Apache Camel K up to 2.8.0/2.9.1/2.10.0 external reference (EUVD-2026-31268)
vuldb·2026-05-21
CVE-2026-45760 [CRITICAL] Apache Camel K up to 2.8.0/2.9.1/2.10.0 external reference (EUVD-2026-31268)
A vulnerability has been found in Apache Camel K up to 2.8.0/2.9.1/2.10.0 and classified as critical. This impacts an unknown function. This manipulation causes externally controlled reference.
This vulnerability is handled as CVE-2026-45760. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-21
Published