Multiple security vulnerabilities affecting Apache Karaf versions and Exploitation Status have been identified in Apache Karaf that allow low-privilege users to reach admin and execute code. The affected version range is before 4.4.12.
CVE-2026-92142 (CVSS Important — Severity): A JMX MBean lifecycle bypass allows a viewer-level JMX client to create or remove MBeans with no role check, which combined with a standard JDK MBean that loads classes from a remote URL, gives a path to remote code execution.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting Apache Karaf versions and Exploitation Status have been identified in Apache Karaf that allow low-privilege users to reach admin and execute code. The affected version range is before 4.4.12.
CVE-2026-92142 (CVSS Important — Severity): A JMX MBean lifecycle bypass allows a viewer-level JMX client to create or remove MBeans with no role check, which combined with a standard JDK MBean that loads classes from a remote URL, gives a path to remote code execution.[emaillocker id="1283"]
CVE-2026-91012 (CVSS Important — Severity): A config service path traversal vulnerability lets a user with the “manager” role write files the ACL reserves for admins, such as the user list, allowing them to grant themselves admin.
CVE-2026-91048 (CVSS Moderate — Severity): The jdbc:* commands shipped with no ACL file, allowing any shell user to create a data source from an attacker-controlled JDBC URL, leading to a privilege-escalation-to-RCE chain.
CVE-2026-91085: A missing ACL entry in the config:install command allows a viewer to fetch a file from any URL and write it into the etc folder, which holds users, keys, and ACL files.
These vulnerabilities collectively present a significant risk for administrators who have not patched their systems.
We recommend you to update Apache Karaf to version 4.4.12.
The following reports contain further technical details:
[/emaillocker]