A security notice published on September 28, 2026 describes CVE-2026-91006, rated moderate severity. The affected component is org.apache.karaf:org.apache.karaf.instance.core, in versions earlier than 4.4.12. The supplied text is an automatic translation of a notice in the oss-sec feed and ends before providing all details.
According to the notice, InstanceServiceImpl builds the command line for starting a child Karaf JVM by concatenating strings, then runs it through /bin/sh on Unix or cscript on Windows. The caller-supplied javaOpts value is inserted without quotes; this construction may allow command injection. The supplied notice does not detail exploitation conditions or specific consequences.
Inventory the versions and uses of the instance management service in your environment. If an affected version is present, consult the original notice and Apache Karaf's official guidance to confirm the fix and plan an upgrade to a fixed version, checking compatibility first. Do not treat the brief description as a substitute for assessing your environment.
To consult and verify this issue, search for CVE-2026-91006 in the oss-sec feed and the project's official notices; compare the affected version and the stated fix. If you use AI to summarize or apply the material, submit only necessary excerpts and remove internal data, credentials, and identifiers. Check technical recommendations against the official source before acting.