PT-2026-35386 · Apache · Camel-Infinispan

·

CVE-2026-40858

·

Published

2026-04-27

·

Updated

2026-07-10

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Camel versions 4.0.0 through 4.14.6 Apache Camel versions 4.15.0 through 4.18.1 Apache Camel versions 4.19.0 through 4.19.9
Description A flaw in the camel-infinispan component allows a remote attacker with write access to the Infinispan cache to execute arbitrary code. The issue occurs when the ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using the ObjectInputStream function without applying an ObjectInputFilter. By injecting a specially crafted serialized Java object, an attacker can trigger code execution during standard aggregation repository operations, such as get() or recover(), within the application context.
Recommendations Update Apache Camel to version 4.14.7 or later for the 4.0.x branch. Update Apache Camel to version 4.18.2 or later for the 4.15.x branch. Update Apache Camel to version 4.20.0 or later for the 4.19.x branch.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06061
CVE-2026-40858
GHSA-4XWX-HVV7-7PRJ

Affected Products

Camel-Infinispan