A security notice published on September 28, 2026 describes CVE-2026-92142, an important flaw in Apache Karaf versions before 4.4.12. The issue affects JMX MBean lifecycle operations and may allow authorization controls to be bypassed.
According to the notice, Karaf protects its JMX MBeanServer with KarafMBeanServerGuard, which applies role-based access control to operations invoked through the remote JMX connector. The connector uses an RMI registry/server and, according to the publication, is enabled by default on ports 1099 and 44444. The available text does not detail the full technical cause.
To assess exposure, identify the Karaf versions in use and check whether a remote JMX connector is enabled and reachable. The notice identifies versions before 4.4.12 as affected; confirm the fix and applicable guidance in the original publication before planning an upgrade.
Consult the original notice in the oss-sec feed and compare its details—especially the CVE identifier, date, and version range—with your organization’s security records and inventory. If you use AI to summarize or apply the material, submit only necessary excerpts and remove names, credentials, addresses, and internal infrastructure details.