Skip to content
Rota Nacional

Cyber ·

CVE-2026-91085: Apache Karaf ACL flaw

A September 28, 2026 advisory reports privilege escalation to administrator in Apache Karaf versions before 4.4.12, due to a missing ACL rule for config:install.

Published on September 28, 2026, the CVE-2026-91085 advisory rates a flaw in Apache Karaf versions before 4.4.12 as moderate. The issue concerns the config:install command and a missing ACL rule, which may allow privilege escalation to administrator.

According to the text, shell/SSH commands are protected by scope-specific ACL configuration files. The described check finds no matching rule for the command and, in that case, fails permissively. The material is an automatic translation of content from the oss-sec feed; consult the original publication in the feed archive and verify the Karaf version and technical details before deciding what to do. The available excerpt does not state remediation steps beyond the reference to version 4.4.12.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free