PT-2026-102461 · Apache · Apache Karaf

·

CVE-2026-91012

·

Published

2026-09-29

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Karaf (affected versions not specified)
Description An issue exists in the org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties) function, which supports the config MBean and config shell commands. The software derives the configuration file path from user-supplied input without verifying that the resulting path remains within the ${karaf.etc} directory. This occurs in two ways: if the property map includes a felix.fileinstall.filename entry, the value is converted directly into a File object, allowing it to point to any absolute path the process can write to; otherwise, the configuration PID is concatenated into the filename, allowing PIDs containing .. segments to resolve outside the intended directory. The createFactoryConfiguration() function is similarly affected via the factory PID or alias. Users with the manager role can exploit this to write controlled content to sensitive files, such as etc/users.properties or etc/org.apache.karaf.management.cfg, potentially granting themselves admin privileges or taking over the container.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91012

Affected Products

Apache Karaf