This is an automated email from the ASF dual-hosted git repository.

jbonofre pushed a commit to branch trunk
in repository https://gitbox.apache.org/repos/asf/karaf-site.git


The following commit(s) were added to refs/heads/trunk by this push:
     new 373c381  Disclose CVE-2026-91085
373c381 is described below

commit 373c3814fee1af8b7406cb51b012e9708c2b3f6f
Author: JB Onofré <[email protected]>
AuthorDate: Mon Sep 28 18:04:15 2026 +0200

    Disclose CVE-2026-91085
---
 documentation.html          |  7 ++++++
 security/cve-2026-91085.txt | 52 +++++++++++++++++++++++++++++++++++++++++++++
 2 files changed, 59 insertions(+)

diff --git a/documentation.html b/documentation.html
index da97a61..c5b4b27 100644
--- a/documentation.html
+++ b/documentation.html
@@ -242,6 +242,13 @@ permalink: /documentation
       <a class="btn btn-outline-primary btn-sm" 
href="/security/cve-2026-91048.txt">Notes &raquo;</a>
     </div>
   </div>
+  <div class="k-admonition">
+    <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
+    <div>
+      <p>CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows 
privilege escalation to admin</p>
+      <a class="btn btn-outline-primary btn-sm" 
href="/security/cve-2026-91085.txt">Notes &raquo;</a>
+    </div>
+  </div>
   <div class="k-admonition">
     <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
     <div>
diff --git a/security/cve-2026-91085.txt b/security/cve-2026-91085.txt
new file mode 100644
index 0000000..0f1628b
--- /dev/null
+++ b/security/cve-2026-91085.txt
@@ -0,0 +1,52 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA256
+
+CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows 
privilege escalation to admin
+
+Severity: moderate 
+
+Affected versions:
+
+- - Apache Karaf before 4.4.12
+
+Description:
+
+Apache Karaf's shell/SSH command security is enforced by per-scope ACL 
configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). 
SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an 
invocation and, when no ACL rule matches the command, fails open: 
ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety 
valve for this, karaf.secured.command.compulsory.roles, ships commented out in 
etc/system.properties, so an unmatched command is all [...]
+
+The shipped org.apache.karaf.command.acl.config ACL 
(assemblies/features/standard/src/main/feature/feature.xml, mirrored into 
instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. 
It restricts delete to admin, restricts edit/property-*/update on the 
jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* 
PIDs to admin, and allows manager for everything else, but config:install was 
simply unmatched, and therefore allowed for any authenticated [...]
+
+config:install <url> <finalname> fetches url and writes it into ${karaf.etc} 
as finalname. It calls PathUtils.checkWithin() to block .. traversal outside 
karaf.etc, but that folder holds every security-relevant file Karaf ships: 
users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* 
files, including the very ACL file that (mis)governs this command. With 
-o/--override, an existing file is overwritten with attacker-controlled bytes 
fetched from an arbitrary URL.
+
+Because felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix 
FileInstall also watches and reloads any .cfg file dropped there, closing the 
loop without requiring a restart.
+
+By contrast, bundle:install, feature:install and kar:install are all 
admin-only in their own ACLs, and config:delete is admin in this same ACL, 
config:install was the outlier.
+
+Mitigation
+
+Add install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the 
file is absent), and/or set karaf.secured.command.compulsory.roles=admin in 
etc/system.properties (and restart) to make unmatched commands fail closed by 
default.
+
+Credit:
+
+Rin Ray <[email protected]> (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-91085
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6jjMbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52dCIP/3zxXr4+H63MMYdCO+cu
+dkOAdiF86gz+y/8KbkvvHNvXiR2h/W8Cx7DDMXHswZhqHMTHC6U38pcumJeCOnWM
+IJvYMUYzNGz0ORsMv/BnitMIFGZ8e75GLpN6/w2G2mOeS85ibimj9HE/XzVIKL39
+GdWE2YwSGsFv7bW6lDEU1+OadiXei1P50Mq6JkRg2pLqTNn2yFS34RQlSlKtS1Vb
+Ucgahwx2RE45x0oB4m/ph3txlvbcj1vJOa2Mx0mfDSc3Bn93PTmsDrCR3pahPBHK
+5/YU4GV4FF+Y5LYQC397ZOlAW+6VVlqzA+nsRhHGKOsZoGbTqrLbSH206Xmdghr1
+G+GKMQYGnwsiHZT+u2c+HqTFgjufYj6lcgJNvaG4TYsBMtiwUYWap6ddpZIaUyV+
+o/UtcQNOiN1+GEMgud2vrtwkR4dQKdUjNWyT5fPywBbsIXPAapGo0xmwkP/KbASX
+v1euIFwWC7Azzl5OC2PdirnopjxZ6a3XuVX4olmbx8mcheixLmuLHB8btSx7rajS
+N4g7DPVbJCmIwNIkc3fyd6c/1UuHaBsx0juomd0KY/lybagLAW6xEZLklXApYofx
+c3DFfJbRyEjlFv62hKQva71nPFZG1O1JHZpvxvOYlTidUGiTXcJvHI3a27RYzATP
+OG9zW1Gybi56CgohRuJugNKb
+=7Z0Q
+-----END PGP SIGNATURE-----

Reply via email to