PT-2026-102462 · Apache · Apache Karaf

·

CVE-2026-91048

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Karaf (affected versions not specified)
Description Missing authorization in the jdbc and jms shell command scopes allows authenticated users, including those with only the viewer role, to execute any jdbc:* and jms:* commands. This occurs because the command guard SecuredSessionFactoryImpl allows commands that lack a matching Access Control List (ACL) rule. Specifically, the jdbc:ds-create command allows the storage of an unvalidated, attacker-controlled JDBC URL into a pax-jdbc-config factory configuration, which is then converted into a live DataSource. Since some JDBC drivers execute code or SQL based on URL parameters, a user with viewer privileges can achieve arbitrary code execution, bypassing the administrative role requirements typically protecting shell:exec.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91048

Affected Products

Apache Karaf