As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create
Apache Karaf versions before 4.4.12 lack an access control list (ACL) configuration file for the jdbc shell command scope, causing the command guard to treat these commands as allowed. Any authenticated user, including those with minimal viewer permissions, can execute jdbc:* commands and use jdbc:ds-create to achieve remote code execution (RCE) by storing attacker-controlled input.
Why it matters: Organizations running Apache Karaf before version 4.4.12 should patch immediately: any authenticated shell user can escalate privileges to RCE, bypassing intended role-based restrictions.
- Source published
- First seen by Cybersecurity Tracker