This is an automated email from the ASF dual-hosted git repository.
jbonofre pushed a commit to branch trunk
in repository https://gitbox.apache.org/repos/asf/karaf-site.git
The following commit(s) were added to refs/heads/trunk by this push:
new 90fb009 Disclose CVE-2026-91012
90fb009 is described below
commit 90fb009c95f91df3514ad5b257d3af62667a6442
Author: JB Onofré <[email protected]>
AuthorDate: Mon Sep 28 17:26:53 2026 +0200
Disclose CVE-2026-91012
---
documentation.html | 7 +++++++
security/cve-2026-91012.txt | 50 +++++++++++++++++++++++++++++++++++++++++++++
2 files changed, 57 insertions(+)
diff --git a/documentation.html b/documentation.html
index 0aed746..24787dc 100644
--- a/documentation.html
+++ b/documentation.html
@@ -228,6 +228,13 @@ permalink: /documentation
<a class="btn btn-outline-primary btn-sm"
href="/security/cve-2026-91006.txt">Notes »</a>
</div>
</div>
+ <div class="k-admonition">
+ <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
+ <div>
+ <p>CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows
Manager-to-Admin Privilege Escalation </p>
+ <a class="btn btn-outline-primary btn-sm"
href="/security/cve-2026-91012.txt">Notes »</a>
+ </div>
+ </div>
<div class="k-admonition">
<div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
<div>
diff --git a/security/cve-2026-91012.txt b/security/cve-2026-91012.txt
new file mode 100644
index 0000000..355e787
--- /dev/null
+++ b/security/cve-2026-91012.txt
@@ -0,0 +1,50 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA256
+
+CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows
Manager-to-Admin Privilege Escalation
+
+Severity: important
+
+Affected versions:
+
+- - Apache Karaf (org.apache.karaf.config.core.impl) before 4.4.12
+
+Description:
+
+org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),
+which backs the "config" MBean and the config:* shell commands, derives the
file
+it writes a configuration to from caller-supplied input without checking that
+the result stays inside ${karaf.etc}:
+
+ * if the submitted property map contains a felix.fileinstall.filename
entry, that value is turned directly into a File (getCfgFileFromProperty), so
it can point to any absolute path the Karaf process can write to;
+ * otherwise the configuration PID is concatenated verbatim into the target
file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a
PID containing ".." segments resolves outside ${karaf.etc}.
createFactoryConfiguration() has the same issue via the factory PID/alias.
+
+Both code paths are reachable by any caller holding the "manager" role under
Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update
= manager"). Such a user can therefore write attacker-controlled content to any
file the Karaf process can write, including files the same ACL otherwise
reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg,
etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user
to grant themselves the admin role or othe [...]
+
+ConfigMBeanImpl.install() and the config:install shell command already guarded
the equivalent risk on their own code path with a finalname.contains("..")
string check, but that check does not stop absolute paths or symlink-based
escapes, and it was never applied to ConfigRepositoryImpl.update() /
createFactoryConfiguration() at all.
+
+Credit:
+
+n0mi1k <[email protected]> (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-91012
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6hrwbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52i5YP/17D5+5aLF0nlVld+QU2
+QmhlL7QvkidS6SnLVj709f5lXqdlbM3NfNkxjNC3gWMblcVogAFa21QLgOOrPq0T
+K3EOpB/5vN0ak148NvUbrB9RhBHj1GlvWpwgsloO4LHgZHryAbGoXqI7/qzVyQhy
+8MGPDwMvG8OYuTtDVaDDvWDlcu2nr1PuVBt5twmYfIEFS+3Gpmwp+uiI50EQh/Rq
+cJhA643XrKAf9+3SrmsxltqG7gtEnlwoDBeYRjJ+FNMSUNm2vX3RbhEY4Qsa5syk
+FGsBm+ish1DipWzQnSYL67uWMIzrywyIFEJU12dOQnvxcoNDYdhnXQGSnxSCnShE
+P9xJMYeyvpMPLy5AjGQ0XC9cy0RyGPForhe82fLmrYBcYL5vEwwOgt/9AqJ7+HeC
+tz0MuUFLUuMw7R+G7w6geN8HSv5arXfW3iK2X5hw9IK2X7dYrx52C+6hFxpCoy/E
+n7mz5MHxkltRoAPzO4RjYYZQRCZSxIpFXQ9TPW2zrk8uR3SuE0v/xsM8MXP7GKyp
+P45Aa3XCABHvAop8wOtCHYwH+7xaljUKck75qcmxpp4RiRA3UoSvxnkUGy96cm6h
+esCpo4MpbqEOa8O+7u8aIV3zX81fnBH6pjXQYaER7WMw3WQkvE5hs8nf9/1TcfO/
+h2aXf0lM+O/QXhrKSWZaJ1Dv
+=LDcl
+-----END PGP SIGNATURE-----