PT-2026-55917 · Apache · Apache Camel

·

CVE-2026-46587

·

Published

2026-05-15

·

Updated

2026-07-06

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Camel versions prior to 4.14.8 Apache Camel versions 4.15.0 through 4.18.2 Apache Camel versions 4.19.0 through 4.20.0
Description Improper input validation in the Couchbase component allows non-Camel-prefixed Exchange headers to bypass the HeaderFilterStrategy, which could enable an operation override from untrusted input.
Recommendations Upgrade to version 4.14.8. Upgrade to version 4.18.3. Upgrade to version 4.21.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09844
CVE-2026-46587
GHSA-46JF-C9VX-HH79

Affected Products

Apache Camel