Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-91048: Apache Karaf lets viewer users run any JDBC command

CVE-2026-91048 · published 3 days ago
Summary

In Apache Karaf, a missing permission file means even a user with only view rights can execute all JDBC‑related shell commands. One of those commands can store a malicious database connection string that is turned into a live data source, allowing the attacker to run code on the server. Upgrade Karaf or add the required permission configuration to restrict JDBC commands to trusted users.

What to do
  • Update apache software foundation apache karaf to version 4.4.12 or later.
Affected software
VendorProductAffected versions
apache software foundation apache karaf < 4.4.12
Original advisory text
Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an "admin misconfiguration".


The same applies to jms:* shell commands.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published29 Sep 2026
Updated2 Oct 2026
First seen29 Sep 2026
Sources
CVE-2026-91048 · MITRE
Track software like this
Free during beta