PT-2026-102463 · Apache · Apache Karaf

·

CVE-2026-91085

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Karaf (affected versions not specified)
Description Security for shell and SSH commands is managed via per-scope Access Control List (ACL) configuration files. The SecuredSessionFactoryImpl.checkSecurity() function fails open when no ACL rule matches a command, as ACLConfigurationParser.Specificity.NO MATCH sets passCheck to true. Since the karaf.secured.command.compulsory.roles safety setting is disabled by default in etc/system.properties, any authenticated user can execute unmatched commands.
The org.apache.karaf.command.acl.config ACL lacks an entry for the config:install command, allowing any authenticated user, including those with only the viewer role, to use it. This command fetches a file from a url and writes it to the ${karaf.etc} directory as finalname. While PathUtils.checkWithin() prevents directory traversal outside ${karaf.etc}, this directory contains critical security files such as users.properties, keys.properties, host.key, and ACL files. Using the -o or --override flag allows an attacker to overwrite these files with arbitrary content from a remote URL. Furthermore, because felix.fileinstall.dir is set to ${karaf.etc}, the Felix FileInstall component automatically reloads modified .cfg files, enabling immediate privilege escalation to admin without a restart.
Recommendations Add install = admin to the etc/org.apache.karaf.command.acl.config.cfg file, creating it if it does not exist. Set karaf.secured.command.compulsory.roles=admin in etc/system.properties and restart the application to ensure unmatched commands fail closed by default.

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91085

Affected Products

Apache Karaf