PT-2026-99845 · Apache · Apache Karaf
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Karaf (affected versions not specified)
Description
The instance-management service (InstanceServiceImpl) constructs the command line for launching a child Karaf JVM using string concatenation, which is then executed via /bin/sh on Unix or cscript on Windows. Because the
javaOpts value provided by the user is inserted into this string without quoting, shell metacharacters such as ;, |, `, or $(...) are interpreted by the shell. This allows for arbitrary OS command execution with the privileges of the Karaf process user. This issue is reachable through the shell commands instance:create, instance:start, instance:restart, and instance:change-opts, as well as the InstanceMBean JMX operations createInstance(), startInstance(), changeJavaOpts(), and cloneInstance().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Set
karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.
Restrict which principals can access instance:* commands and InstancesMBean via etc/users.properties role assignments.
Treat javaOpts passed to instance:create, instance:start, instance:change-opts, and InstancesMBean as untrusted input.OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Karaf