CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7019

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects

CVE-2026-80352 is a code injection vulnerability in Apache Camel K versions 2.0.0 before 2.9.3 and 2.10.1 before 2.10.2. The flaw stems from improper control of YAML code generation in the Master trait serviceAccountName configuration, permitting an authorized custom resource (CR) author to inject arbitrary Kubernetes objects.

Why it matters: Teams running affected Camel K versions must patch immediately; authorized users can exploit this to deploy unauthorized resources in Kubernetes clusters.

VendorsKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects

CVE-2026-80352 is a code injection vulnerability in Apache Camel K versions 2.0.0 before 2.9.3 and 2.10.1 before 2.10.2. A YAML injection flaw in custom resource configuration allows an authorized custom resource author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation or manipulation.

Why it matters: Organizations running affected Apache Camel K versions should patch immediately, as authorized users with custom resource creation privileges can exploit this to deploy malicious Kubernetes objects into clusters.

VendorsKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary