CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7020

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod

Apache Camel K versions before 2.9.3 and 2.10.2 contain an eval injection vulnerability in Maven configuration handling. Tenant-controlled repository content can be leveraged to execute arbitrary code within the operator pod.

Why it matters: Operators running Apache Camel K in multi-tenant environments face critical remote code execution risk; immediate patching to 2.9.3, 2.10.2, or later is required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod

Apache Camel K versions 2.0.0 before 2.9.3 and 2.10.1 before 2.10.2 contain an eval injection vulnerability in Maven configuration handling that allows tenant-controlled repository content to influence code execution within operator pods. The vulnerability stems from improper neutralization of directives in dynamically evaluated code. CVE-2026-80351 carries a CVSS score of 9.8.

Why it matters: Organizations running Apache Camel K must urgently patch affected versions to prevent tenant-controlled repositories from executing arbitrary code in operator pods, which could lead to cluster compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary