CVE-2026-46585P3HIGHCVSS 7.5≥ 4.0.0, < 4.14.8·≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-46585 [HIGH] CWE-20 CVE-2026-46585: Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache
Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Lucene Component.
The camel-lucene producer reads the search phrase from an Exchange header (LuceneConstants.HEADER_QUERY) whose value was the plain string QUERY (and RETURN_LUCENE_DOCS for HEADER_RETURN_LUCENE_DOCS). Because these names do not sta
nvd