CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8761

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-91048: Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create

Apache Karaf versions before 4.4.12 lack an access control list (ACL) configuration file for the jdbc shell command scope, causing the command guard to treat these commands as allowed. Any authenticated user, including those with minimal viewer permissions, can execute jdbc:* commands and use jdbc:ds-create to achieve remote code execution (RCE) by storing attacker-controlled input.

Why it matters: Organizations running Apache Karaf before version 4.4.12 should patch immediately: any authenticated shell user can escalate privileges to RCE, bypassing intended role-based restrictions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary