As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
CVE-2026-91006 affects Apache Karaf before version 4.4.12 and allows OS command injection through the javaOpts parameter in the instance-management service. The vulnerability exists because InstanceServiceImpl builds child JVM launch commands via string concatenation without quoting user-supplied input before executing through shell interpreters.
Why it matters: Organizations running Apache Karaf instances before 4.4.12 that accept javaOpts input from untrusted sources face remote code execution risk; apply the patch immediately if instances are exposed to user-controlled input.
- Source published
- First seen by Cybersecurity Tracker