Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-80352: Apache Camel K allows unauthorized creation of Kubernetes resources
CVE-2026-80352 · published 1 month ago
Summary
A flaw in Apache Camel K’s custom resource setup lets a user with configuration rights add any Kubernetes object, giving them the same privileges as the system operator. This could lead to unwanted resources being created in your cluster. Upgrade to version 2.9.3, 2.10.2 or later to fix the issue.
What to do
- Update apache software foundation apache camel k to version 2.9.3 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache camel k | < 2.9.3 |
| apache | camel |
>= 2.0.0, < 2.9.3 >= 2.10.0, < 2.10.2 cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:* |
Original advisory text
Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.
A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator.
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.
Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator.
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.
Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
References
- https://hub.docker.com URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80352... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-80352 Vendor Advisory
- https://camel.apache.org/security/CVE-2026-80352.html Patch Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/09/10/15 Mailing List Third Party Advisory
Severity
9.8
Critical
Type
CWE-94Code Injection
Timeline
Published10 Sep 2026
Updated9 Oct 2026
First seen10 Sep 2026
Track software like this
Free during beta