Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-91012: Apache Karaf allows manager to become admin via file write

CVE-2026-91012 · published 3 days ago
Summary

Apache Karaf lets users with the manager role change any configuration file the service can write to, including files that control admin permissions. By supplying specially crafted names, a manager can overwrite these files and grant themselves full admin rights. Update Karaf to a version that validates file paths or restrict manager access to trusted users.

What to do
  • Update apache software foundation apache karaf to version 4.4.12 or later.
Affected software
VendorProductAffected versions
apache software foundation apache karaf < 4.4.12
Original advisory text
Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),
which backs the "config" MBean and the config:* shell commands, derives the file
it writes a configuration to from caller-supplied input without checking that
the result stays inside ${karaf.etc}:

* if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;
* otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias.


Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.






ConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains("..") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
Timeline
Published29 Sep 2026
Updated2 Oct 2026
First seen29 Sep 2026
Sources
CVE-2026-91012 · MITRE
Track software like this
Free during beta