CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7018

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace

CVE-2026-80354 is an authorization bypass vulnerability in Apache Camel K affecting versions 2.0.0 through 2.9.3 and 2.10.1 through 2.10.2. The flaw allows tenants to access secrets in the operator namespace through the mavenProfiles ValueSources configuration, potentially exposing sensitive data belonging to other tenants or the operator itself.

Why it matters: Organizations running vulnerable Camel K clusters should upgrade immediately, as multi-tenant deployments face exposure of cross-tenant secrets and operator credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary