Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-91048: Apache Karaf lets viewer users run any JDBC command
CVE-2026-91048 · published 3 days ago
Summary
In Apache Karaf, a missing permission file means even a user with only view rights can execute all JDBC‑related shell commands. One of those commands can store a malicious database connection string that is turned into a live data source, allowing the attacker to run code on the server. Upgrade Karaf or add the required permission configuration to restrict JDBC commands to trusted users.
What to do
- Update apache software foundation apache karaf to version 4.4.12 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache karaf | < 4.4.12 |
Original advisory text
Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an "admin misconfiguration".
The same applies to jms:* shell commands.
The same applies to jms:* shell commands.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-862Missing Authorization
Timeline
Published29 Sep 2026
Updated2 Oct 2026
First seen29 Sep 2026
Track software like this
Free during beta