PT-2026-102459 · Apache · Apache Karaf

·

CVE-2026-92142

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Karaf versions prior to 4.4.12 Apache Karaf versions prior to 4.5.0
Description Apache Karaf contains a flaw in the KarafMBeanServerGuard which fails to enforce role-based access control (RBAC) on specific MBean lifecycle operations. The createMBean(), registerMBean(), and unregisterMBean() functions are not included in the guarded operations list, allowing any authenticated user, including those with the least-privileged "viewer" role, to instantiate arbitrary classes as MBeans without authorization or audit logs. This can be exploited to instantiate the javax.management.loading.MLet class, which serves as a remote classloader. By invoking the getMBeansFromURL() operation—which is permitted for the "viewer" role due to a wildcard rule matching "get*"—an attacker can fetch a remote MLet file and execute arbitrary code within the Karaf JVM.
Recommendations Upgrade to version 4.4.12 or 4.5.0 or later. Restrict network access to the JMX RMI registry/server ports 1099 and 44444 to trusted hosts. Avoid issuing JMX credentials to any users who do not require the "admin" role.

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92142

Affected Products

Apache Karaf