🔐 CVE Alert

CVE-2026-91048

UNKNOWN 0.0

Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an "admin misconfiguration". The same applies to jms:* shell commands.

CWE CWE-862
Vendor apache software foundation
Product apache karaf
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache karaf

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache karaf are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Karaf
0 < 4.4.12

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/ph3867mxh2tft75w0o1hpn10f5mbmw32 openwall.com: http://www.openwall.com/lists/oss-security/2026/09/28/9

Credits

🔍 MopMonk-AI <[email protected]>