CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8762

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation

Apache Karaf versions before 4.4.12 contain a path traversal vulnerability in the config service that allows an authenticated manager-level user to write configuration files outside the intended directory. An attacker with manager privileges can exploit CVE-2026-91012 to escalate to admin-level access by manipulating the ConfigRepositoryImpl update method to bypass directory restrictions.

Why it matters: Operators running Apache Karaf before 4.4.12 face privilege escalation risk if any manager-role users are compromised or untrusted, requiring immediate patching to prevent unauthorized admin access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary