Skip to content
Rota Nacional

Cyber ·

Apache Karaf: JMX authorization flaw fixed in version 4.4.12

A security notice published on September 28, 2026 reports that Apache Karaf versions before 4.4.12 allow authorization controls to be bypassed in JMX MBean lifecycle operations.

A security notice published on September 28, 2026 describes CVE-2026-92142, an important flaw in Apache Karaf versions before 4.4.12. The issue affects JMX MBean lifecycle operations and may allow authorization controls to be bypassed.

According to the notice, Karaf protects its JMX MBeanServer with KarafMBeanServerGuard, which applies role-based access control to operations invoked through the remote JMX connector. The connector uses an RMI registry/server and, according to the publication, is enabled by default on ports 1099 and 44444. The available text does not detail the full technical cause.

To assess exposure, identify the Karaf versions in use and check whether a remote JMX connector is enabled and reachable. The notice identifies versions before 4.4.12 as affected; confirm the fix and applicable guidance in the original publication before planning an upgrade.

Consult the original notice in the oss-sec feed and compare its details—especially the CVE identifier, date, and version range—with your organization’s security records and inventory. If you use AI to summarize or apply the material, submit only necessary excerpts and remove names, credentials, addresses, and internal infrastructure details.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free