← All Advisories

CVE-2026-91012

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-91012

Key Details

CVECVE-2026-91012
CVSS Score / Version9.8 (Critical) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsApache Software Foundation Apache Karaf
Classified asCWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Apache Software FoundationApache Karaf
SubsystemsGeneral OT
SectorsMultiple

What to Know

org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),

which backs the "config" MBean and the config:* shell commands, derives the file

it writes a configuration to from caller-supplied input without checking that

the result stays inside ${karaf.etc}:

* if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;

* otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias.

Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.

ConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains("..") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all. (NVD)

What to Do

Monitor Apache Software Foundation's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-91012
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-91012