PT-2026-102459 · Apache · Apache Karaf
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Karaf versions prior to 4.4.12
Apache Karaf versions prior to 4.5.0
Description
Apache Karaf contains a flaw in the
KarafMBeanServerGuard which fails to enforce role-based access control (RBAC) on specific MBean lifecycle operations. The createMBean(), registerMBean(), and unregisterMBean() functions are not included in the guarded operations list, allowing any authenticated user, including those with the least-privileged "viewer" role, to instantiate arbitrary classes as MBeans without authorization or audit logs. This can be exploited to instantiate the javax.management.loading.MLet class, which serves as a remote classloader. By invoking the getMBeansFromURL() operation—which is permitted for the "viewer" role due to a wildcard rule matching "get*"—an attacker can fetch a remote MLet file and execute arbitrary code within the Karaf JVM.Recommendations
Upgrade to version 4.4.12 or 4.5.0 or later.
Restrict network access to the JMX RMI registry/server ports 1099 and 44444 to trusted hosts.
Avoid issuing JMX credentials to any users who do not require the "admin" role.
Fix
RCE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Karaf