CVE-2026-91012: Apache Karaf flaw may elevate privileges
A notice published on September 28, 2026 reports a path traversal flaw in Apache Karaf configuration services before version 4.4.12, with possible privilege escalation.
A notice published on September 28, 2026 describes CVE-2026-91012 in Apache Karaf. According to the text, versions earlier than 4.4.12 may allow privilege escalation through a path traversal flaw in org.apache.karaf.config.core.impl. The notice title specifies a possible escalation from manager to admin.
The description identifies ConfigRepositoryImpl#update(pid, properties), used by the “config” MBean and config:* shell commands. It selects a configuration file based on data supplied by the caller without checking that the resulting path remains inside ${karaf.etc}. The available excerpt ends mid-description; consult the original oss-sec mailing-list notice by CVE identifier and verify versions and guidance before acting. If using AI to analyze the material, do not submit configurations, credentials, or internal data.