PT-2026-99845 · Apache · Apache Karaf

·

CVE-2026-91006

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Karaf (affected versions not specified)
Description The instance-management service (InstanceServiceImpl) constructs the command line for launching a child Karaf JVM using string concatenation, which is then executed via /bin/sh on Unix or cscript on Windows. Because the javaOpts value provided by the user is inserted into this string without quoting, shell metacharacters such as ;, |, `, or $(...) are interpreted by the shell. This allows for arbitrary OS command execution with the privileges of the Karaf process user. This issue is reachable through the shell commands instance:create, instance:start, instance:restart, and instance:change-opts, as well as the InstanceMBean JMX operations createInstance(), startInstance(), changeJavaOpts(), and cloneInstance().
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. Restrict which principals can access instance:* commands and InstancesMBean via etc/users.properties role assignments. Treat javaOpts passed to instance:create, instance:start, instance:change-opts, and InstancesMBean as untrusted input.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91006

Affected Products

Apache Karaf