TL;DR
The Apache Karaf project has fixed four Apache Karaf vulnerabilities in version 4.4.12. Two are rated important and two moderate. Each lets a user with a low-privilege role, such as “viewer” or “manager”, climb to admin or run code in the Karaf JVM.
CISA KEV isn't the only exploit signal for Apache CVEs. Pro/Team adds a second confirmed-exploit feed.
Try free for 14 daysWhy These Apache Karaf Vulnerabilities Matter
Apache Karaf is a modulith runtime for Java applications. It supports REST APIs, web apps, and Spring Boot, and ships a remote shell and JMX management interface. Karaf protects those interfaces with role-based access control. The four flaws all punch holes in that control.
In practice, any account with the weakest role becomes a risk. A leaked read-only credential could turn into full control of the container.
How the Attacks Work
CVE-2026-92142: JMX MBean Lifecycle Bypass (Important)
Karaf’s JMX guard only checks a fixed list of operations. MBean creation, registration, and removal were not on that list. So any authenticated JMX user, even a “viewer”, could create or remove MBeans with no role check and no audit log entry.
That gap becomes dangerous when combined with a standard JDK MBean that loads classes from a remote URL. The default ACL grants “viewer” access to any method whose name starts with “get”. The URL-loading method happens to match that rule. Together, these gaps give a viewer-level JMX client a path to remote code execution. The JMX connector listens by default on ports 1099 and 44444.
CVE-2026-91012: Config Service Path Traversal (Important)
The component behind the config MBean and config:* shell commands builds file paths from caller input. It never checks that the result stays inside the Karaf etc directory. A user with the “manager” role can therefore write files the ACL reserves for admins, such as the user list. That lets them grant themselves admin.
CVE-2026-91085: config:install Missing ACL Entry (Moderate)
Karaf’s shell allows any command that has no matching ACL rule. The shipped config ACL had no entry for config:install. As a result, a viewer could fetch a file from any URL and write it into the etc folder, which holds users, keys, and ACL files. Karaf reloads those files without a restart.
CVE-2026-91048: jdbc:* Commands Reach Code Execution (Moderate)
The jdbc command scope shipped with no ACL file at all. Any shell user could create a data source from an attacker-controlled JDBC URL. Some JDBC drivers run code at connection time based on URL parameters. The advisory warns this is “a privilege-escalation-to-RCE chain, not merely an admin misconfiguration.” The same gap affects jms:* commands.
Affected Versions and Exploitation Status
All four flaws affect Apache Karaf before 4.4.12. The advisory does not report any exploitation in the wild, and no public proof-of-concept has been confirmed.
Patch and Mitigation Steps
Upgrade to Apache Karaf 4.4.12, or to 4.5.0 once it ships. You can get the fixed release from the official Apache Karaf download page. If you cannot upgrade yet, take these steps:
- Restrict network access to JMX ports 1099 and 44444 to trusted hosts.
- Avoid issuing non-admin JMX credentials.
- Add “install = admin” to the config command ACL file.
- Set karaf.secured.command.compulsory.roles=admin in etc/system.properties, then restart, so unmatched commands fail closed.
Because these Apache Karaf vulnerabilities turn read-only accounts into admin access, audit every non-admin role before and after you patch.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!