CVE-2026-91012
published 2026-09-29CVE-2026-91012: org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.45%
37.2th percentile
org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),
which backs the "config" MBean and the config:* shell commands, derives the file
it writes a configuration to from caller-supplied input without checking that
the result stays inside ${karaf.etc}:
* if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;
* otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias.
Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.
ConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains("..") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all.Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_karaf | < 4.4.12 | 4.4.12 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service
vendor_redhat·2026-09-29·CVSS 8.8
CVE-2026-91012 [HIGH] CWE-22 org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service
org.apache.karaf.config/org.apache.karaf.config.core: Apache Karaf: Privilege escalation via path traversal in configuration service
A flaw was found in Apache Karaf. This vulnerability allows privilege escalation when the configuration service fails to properly restrict file paths to the designated configuration directory. An authenticated user with manager-level permissions can supply directory traversal sequences or absolute file paths to write attacker-controlled content to arbitrary files. Successful exploitation enables the attacker to grant themselves administrative privileges and achieve full container takeover.
Statement: This vulnerability is rated as Important because an authenticated user with low-level managerial privileges can breach role boundaries to gain full administrat
GHSA
org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from calle
ghsa_unreviewed·2026-09-29
CVE-2026-91012 org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from calle
org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),
which backs the "config" MBean and the config:* shell commands, derives the file
it writes a configuration to from caller-supplied input without checking that
the result stays inside ${karaf.etc}:
* if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;
* otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias.
Both code paths ar
No detection rules found.
No public exploits indexed.
2026-09-29
Published