CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8744

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)

CVE-2026-91006 affects Apache Karaf before version 4.4.12 and allows OS command injection through the javaOpts parameter in the instance-management service. The vulnerability exists because InstanceServiceImpl builds child JVM launch commands via string concatenation without quoting user-supplied input before executing through shell interpreters.

Why it matters: Organizations running Apache Karaf instances before 4.4.12 that accept javaOpts input from untrusted sources face remote code execution risk; apply the patch immediately if instances are exposed to user-controlled input.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary