As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace
CVE-2026-80354 is an authorization bypass vulnerability in Apache Camel K affecting versions 2.0.0 through 2.9.3 and 2.10.1 through 2.10.2. The flaw allows tenants to access secrets in the operator namespace through the mavenProfiles ValueSources configuration, potentially exposing sensitive data belonging to other tenants or the operator itself.
Why it matters: Organizations running vulnerable Camel K clusters should upgrade immediately, as multi-tenant deployments face exposure of cross-tenant secrets and operator credentials.
- Source published
- First seen by Cybersecurity Tracker