As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects
CVE-2026-80352 is a code injection vulnerability in Apache Camel K versions 2.0.0 before 2.9.3 and 2.10.1 before 2.10.2. The flaw stems from improper control of YAML code generation in the Master trait serviceAccountName configuration, permitting an authorized custom resource (CR) author to inject arbitrary Kubernetes objects.
Why it matters: Teams running affected Camel K versions must patch immediately; authorized users can exploit this to deploy unauthorized resources in Kubernetes clusters.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects
CVE-2026-80352 is a code injection vulnerability in Apache Camel K versions 2.0.0 before 2.9.3 and 2.10.1 before 2.10.2. A YAML injection flaw in custom resource configuration allows an authorized custom resource author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation or manipulation.
Why it matters: Organizations running affected Apache Camel K versions should patch immediately, as authorized users with custom resource creation privileges can exploit this to deploy malicious Kubernetes objects into clusters.
- Source published
- First seen by Cybersecurity Tracker