As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
Apache Karaf versions before 4.4.12 contain a privilege escalation vulnerability (CVE-2026-91085) in which the config:install command lacks a required access control list (ACL) entry. When no ACL rule matches a command, the security check fails open, allowing authentication bypass and elevation to admin rights.
Why it matters: Operators running Apache Karaf before version 4.4.12 face privilege escalation risk; apply the patch to restore proper ACL enforcement on shell and SSH commands.
- Source published
- First seen by Cybersecurity Tracker