CVE-2026-49099P4MEDIUMCVSS 5.3≥ 4.0.0, < 4.14.8·≥ 4.15.0, < 4.18.3+1 more2026-07-06
CVE-2026-49099 [MEDIUM] CWE-74 CVE-2026-49099: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'),
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Salesforce Component.
The camel-salesforce producer resolves its operation parameters - the SOQL query, the SOSL search, the target SObject name and id, the Apex REST URL an
nvd