This is an automated email from the ASF dual-hosted git repository.
jbonofre pushed a commit to branch trunk
in repository https://gitbox.apache.org/repos/asf/karaf-site.git
The following commit(s) were added to refs/heads/trunk by this push:
new 373c381 Disclose CVE-2026-91085
373c381 is described below
commit 373c3814fee1af8b7406cb51b012e9708c2b3f6f
Author: JB Onofré <[email protected]>
AuthorDate: Mon Sep 28 18:04:15 2026 +0200
Disclose CVE-2026-91085
---
documentation.html | 7 ++++++
security/cve-2026-91085.txt | 52 +++++++++++++++++++++++++++++++++++++++++++++
2 files changed, 59 insertions(+)
diff --git a/documentation.html b/documentation.html
index da97a61..c5b4b27 100644
--- a/documentation.html
+++ b/documentation.html
@@ -242,6 +242,13 @@ permalink: /documentation
<a class="btn btn-outline-primary btn-sm"
href="/security/cve-2026-91048.txt">Notes »</a>
</div>
</div>
+ <div class="k-admonition">
+ <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
+ <div>
+ <p>CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows
privilege escalation to admin</p>
+ <a class="btn btn-outline-primary btn-sm"
href="/security/cve-2026-91085.txt">Notes »</a>
+ </div>
+ </div>
<div class="k-admonition">
<div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
<div>
diff --git a/security/cve-2026-91085.txt b/security/cve-2026-91085.txt
new file mode 100644
index 0000000..0f1628b
--- /dev/null
+++ b/security/cve-2026-91085.txt
@@ -0,0 +1,52 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA256
+
+CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows
privilege escalation to admin
+
+Severity: moderate
+
+Affected versions:
+
+- - Apache Karaf before 4.4.12
+
+Description:
+
+Apache Karaf's shell/SSH command security is enforced by per-scope ACL
configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg).
SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an
invocation and, when no ACL rule matches the command, fails open:
ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety
valve for this, karaf.secured.command.compulsory.roles, ships commented out in
etc/system.properties, so an unmatched command is all [...]
+
+The shipped org.apache.karaf.command.acl.config ACL
(assemblies/features/standard/src/main/feature/feature.xml, mirrored into
instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry.
It restricts delete to admin, restricts edit/property-*/update on the
jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.*
PIDs to admin, and allows manager for everything else, but config:install was
simply unmatched, and therefore allowed for any authenticated [...]
+
+config:install <url> <finalname> fetches url and writes it into ${karaf.etc}
as finalname. It calls PathUtils.checkWithin() to block .. traversal outside
karaf.etc, but that folder holds every security-relevant file Karaf ships:
users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.*
files, including the very ACL file that (mis)governs this command. With
-o/--override, an existing file is overwritten with attacker-controlled bytes
fetched from an arbitrary URL.
+
+Because felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix
FileInstall also watches and reloads any .cfg file dropped there, closing the
loop without requiring a restart.
+
+By contrast, bundle:install, feature:install and kar:install are all
admin-only in their own ACLs, and config:delete is admin in this same ACL,
config:install was the outlier.
+
+Mitigation
+
+Add install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the
file is absent), and/or set karaf.secured.command.compulsory.roles=admin in
etc/system.properties (and restart) to make unmatched commands fail closed by
default.
+
+Credit:
+
+Rin Ray <[email protected]> (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-91085
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6jjMbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52dCIP/3zxXr4+H63MMYdCO+cu
+dkOAdiF86gz+y/8KbkvvHNvXiR2h/W8Cx7DDMXHswZhqHMTHC6U38pcumJeCOnWM
+IJvYMUYzNGz0ORsMv/BnitMIFGZ8e75GLpN6/w2G2mOeS85ibimj9HE/XzVIKL39
+GdWE2YwSGsFv7bW6lDEU1+OadiXei1P50Mq6JkRg2pLqTNn2yFS34RQlSlKtS1Vb
+Ucgahwx2RE45x0oB4m/ph3txlvbcj1vJOa2Mx0mfDSc3Bn93PTmsDrCR3pahPBHK
+5/YU4GV4FF+Y5LYQC397ZOlAW+6VVlqzA+nsRhHGKOsZoGbTqrLbSH206Xmdghr1
+G+GKMQYGnwsiHZT+u2c+HqTFgjufYj6lcgJNvaG4TYsBMtiwUYWap6ddpZIaUyV+
+o/UtcQNOiN1+GEMgud2vrtwkR4dQKdUjNWyT5fPywBbsIXPAapGo0xmwkP/KbASX
+v1euIFwWC7Azzl5OC2PdirnopjxZ6a3XuVX4olmbx8mcheixLmuLHB8btSx7rajS
+N4g7DPVbJCmIwNIkc3fyd6c/1UuHaBsx0juomd0KY/lybagLAW6xEZLklXApYofx
+c3DFfJbRyEjlFv62hKQva71nPFZG1O1JHZpvxvOYlTidUGiTXcJvHI3a27RYzATP
+OG9zW1Gybi56CgohRuJugNKb
+=7Z0Q
+-----END PGP SIGNATURE-----