Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-80352: Apache Camel K allows unauthorized creation of Kubernetes resources

CVE-2026-80352 · published 1 month ago
Summary

A flaw in Apache Camel K’s custom resource setup lets a user with configuration rights add any Kubernetes object, giving them the same privileges as the system operator. This could lead to unwanted resources being created in your cluster. Upgrade to version 2.9.3, 2.10.2 or later to fix the issue.

What to do
  • Update apache software foundation apache camel k to version 2.9.3 or later.
Affected software
VendorProductAffected versions
apache software foundation apache camel k < 2.9.3
apache camel >= 2.0.0, < 2.9.3
>= 2.10.0, < 2.10.2
cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*
Original advisory text
Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.



A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator.



This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.



Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-94Code Injection
Timeline
Published10 Sep 2026
Updated9 Oct 2026
First seen10 Sep 2026
Sources
CVE-2026-80352 · MITRE
Track software like this
Free during beta