๐Ÿ” CVE Alert

CVE-2026-80351

CRITICAL 9.8

Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.

CWE CWE-95
Vendor apache software foundation
Product apache camel k
Published Sep 10, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache camel k

Be the first to know when new critical vulnerabilities affecting apache software foundation apache camel k are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Camel K
2.0.0 < 2.9.3 2.10.1 < 2.10.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
camel.apache.org: https://camel.apache.org/security/CVE-2026-80351.html openwall.com: http://www.openwall.com/lists/oss-security/2026/09/10/14