CVE-2026-40022P3HIGHCVSS 8.2≥ 4.14.1, < 4.14.6·≥ 4.18.0, < 4.18.22026-04-27
CVE-2026-40022 [HIGH] CWE-288 CVE-2026-40022: When authentication is enabled on the Apache Camel embedded HTTP server or embedded management serve
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes derive the authentication path from p
nvd