๐Ÿ” CVE Alert

CVE-2026-80354

HIGH 8.1

Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.

CWE CWE-639
Vendor apache software foundation
Product apache camel k
Published Sep 10, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache camel k

Be the first to know when new high vulnerabilities affecting apache software foundation apache camel k are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Camel K
2.0.0 < 2.9.3 2.10.1 < 2.10.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
camel.apache.org: https://camel.apache.org/security/CVE-2026-80354.html openwall.com: http://www.openwall.com/lists/oss-security/2026/09/10/16