Skip to content
Rota Nacional

Cyber ·

CVE-2026-91012: Apache Karaf flaw may elevate privileges

A notice published on September 28, 2026 reports a path traversal flaw in Apache Karaf configuration services before version 4.4.12, with possible privilege escalation.

A notice published on September 28, 2026 describes CVE-2026-91012 in Apache Karaf. According to the text, versions earlier than 4.4.12 may allow privilege escalation through a path traversal flaw in org.apache.karaf.config.core.impl. The notice title specifies a possible escalation from manager to admin.

The description identifies ConfigRepositoryImpl#update(pid, properties), used by the “config” MBean and config:* shell commands. It selects a configuration file based on data supplied by the caller without checking that the resulting path remains inside ${karaf.etc}. The available excerpt ends mid-description; consult the original oss-sec mailing-list notice by CVE identifier and verify versions and guidance before acting. If using AI to analyze the material, do not submit configurations, credentials, or internal data.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free