Apache · Apache Karaf · CVE-2026-91048
**Name of the Vulnerable Software and Affected Versions**
Apache Karaf (affected versions not specified)
**Description**
Missing authorization in the `jdbc` and `jms` shell command scopes allows authenticated users, including those with only the `viewer` role, to execute any `jdbc:*` and `jms:*` commands. This occurs because the command guard `SecuredSessionFactoryImpl` allows commands that lack a matching Access Control List (ACL) rule. Specifically, the `jdbc:ds-create` command allows the storage of an unvalidated, attacker-controlled JDBC URL into a `pax-jdbc-config` factory configuration, which is then converted into a live `DataSource`. Since some JDBC drivers execute code or SQL based on URL parameters, a user with `viewer` privileges can achieve arbitrary code execution, bypassing the administrative role requirements typically protecting `shell:exec`.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.