Apache · Apache Karaf · CVE-2026-91085
**Name of the Vulnerable Software and Affected Versions**
Apache Karaf (affected versions not specified)
**Description**
Security for shell and SSH commands is managed via per-scope Access Control List (ACL) configuration files. The `SecuredSessionFactoryImpl.checkSecurity()` function fails open when no ACL rule matches a command, as `ACLConfigurationParser.Specificity.NO MATCH` sets `passCheck` to true. Since the `karaf.secured.command.compulsory.roles` safety setting is disabled by default in `etc/system.properties`, any authenticated user can execute unmatched commands.
The `org.apache.karaf.command.acl.config` ACL lacks an entry for the `config:install` command, allowing any authenticated user, including those with only the `viewer` role, to use it. This command fetches a file from a `url` and writes it to the `${karaf.etc}` directory as `finalname`. While `PathUtils.checkWithin()` prevents directory traversal outside `${karaf.etc}`, this directory contains critical security files such as `users.properties`, `keys.properties`, `host.key`, and ACL files. Using the `-o` or `--override` flag allows an attacker to overwrite these files with arbitrary content from a remote URL. Furthermore, because `felix.fileinstall.dir` is set to `${karaf.etc}`, the Felix FileInstall component automatically reloads modified `.cfg` files, enabling immediate privilege escalation to admin without a restart.
**Recommendations**
Add `install = admin` to the `etc/org.apache.karaf.command.acl.config.cfg` file, creating it if it does not exist.
Set `karaf.secured.command.compulsory.roles=admin` in `etc/system.properties` and restart the application to ensure unmatched commands fail closed by default.