Skip to content
Rota Nacional

Cyber ·

Apache Karaf: missing ACL rule may enable command execution

A notice published on September 28, 2026 reports that Apache Karaf versions before 4.4.12 may let authenticated sessions run jdbc:* commands without the expected authorization, with a possible path to remote code execution.

The notice, attributed to Jean-Baptiste Onofré and rated moderate severity, describes a flaw in Apache Karaf versions before 4.4.12. The shell's jdbc command scope lacked a corresponding ACL file.

According to the text, SecuredSessionFactoryImpl treats a command with no matching ACL rule as allowed. As a result, any authenticated shell session, including one with only the viewer role, could run jdbc:* commands. The notice points to a possible path to remote code execution. The available excerpt also mentions jdbc:ds-create and an attacker-controlled value, but ends before explaining the mechanism.

Check whether an installation is affected and consult the original oss-sec notice to confirm scope and remediation guidance. The text says versions before 4.4.12 are affected; verify the fixed version and recommended steps in the project's official documentation before changing systems.

If you use AI to analyze configurations, logs, or the notice, remove credentials, personal data, and unnecessary internal details. Compare conclusions with the original notice and test changes in a controlled environment before applying them in production.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free