CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CVE-2026-92142: Apache Karaf: Authorization bypass in JMX MBean lifecycle operations

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8759

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-92142: Apache Karaf: Authorization bypass in JMX MBean lifecycle operations

Apache Karaf before version 4.4.12 contains an authorization bypass vulnerability in its JMX MBean lifecycle operations. The KarafMBeanServerGuard, which enforces role-based access control (RBAC) on remote JMX operations over the default-enabled RMI registry and server on ports 1099 and 44444, fails to protect a fixed list of MBean operations.

Why it matters: Organizations running Apache Karaf versions before 4.4.12 with JMX enabled should prioritize patching to prevent unauthorized remote access to MBean operations that bypass role-based access controls.

VendorsOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary