Author: jbonofre
Date: Mon Sep 28 16:08:00 2026
New Revision: 1938619

Log:
[scm-publish] Updating main website contents

Added:
   karaf/site/production/security/cve-2026-91085.txt
Modified:
   karaf/site/production/documentation.html
   karaf/site/production/feed.xml

Modified: karaf/site/production/documentation.html
==============================================================================
--- karaf/site/production/documentation.html    Mon Sep 28 15:51:59 2026        
(r1938618)
+++ karaf/site/production/documentation.html    Mon Sep 28 16:08:00 2026        
(r1938619)
@@ -370,6 +370,13 @@
   <div class="k-admonition">
     <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
     <div>
+      <p>CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows 
privilege escalation to admin</p>
+      <a class="btn btn-outline-primary btn-sm" 
href="/security/cve-2026-91085.txt">Notes &raquo;</a>
+    </div>
+  </div>
+  <div class="k-admonition">
+    <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
+    <div>
       <p>CVE-2026-92230: Apache Karaf: Improper release of ClassLoader 
references via static ThreadLocal caching</p>
       <a class="btn btn-outline-primary btn-sm" 
href="/security/cve-2026-92230.txt">Notes &raquo;</a>
     </div>

Modified: karaf/site/production/feed.xml
==============================================================================
--- karaf/site/production/feed.xml      Mon Sep 28 15:51:59 2026        
(r1938618)
+++ karaf/site/production/feed.xml      Mon Sep 28 16:08:00 2026        
(r1938619)
@@ -1 +1 @@
-<?xml version="1.0" encoding="utf-8"?><feed 
xmlns="http://www.w3.org/2005/Atom"; ><generator uri="https://jekyllrb.com/"; 
version="4.4.1">Jekyll</generator><link 
href="https://karaf.apache.org/feed.xml"; rel="self" type="application/atom+xml" 
/><link href="https://karaf.apache.org/"; rel="alternate" type="text/html" 
/><updated>2026-09-28T10:51:17-05:00</updated><id>https://karaf.apache.org/feed.xml</id><title
 type="html">Apache Karaf - The modulith runtime</title><subtitle>Karaf 
provides modulith runtime for the enterprise, running on premise or on cloud. 
Focus on your business code and applications, Apache Karaf deals with the 
rest.</subtitle></feed>
\ No newline at end of file
+<?xml version="1.0" encoding="utf-8"?><feed 
xmlns="http://www.w3.org/2005/Atom"; ><generator uri="https://jekyllrb.com/"; 
version="4.4.1">Jekyll</generator><link 
href="https://karaf.apache.org/feed.xml"; rel="self" type="application/atom+xml" 
/><link href="https://karaf.apache.org/"; rel="alternate" type="text/html" 
/><updated>2026-09-28T11:07:18-05:00</updated><id>https://karaf.apache.org/feed.xml</id><title
 type="html">Apache Karaf - The modulith runtime</title><subtitle>Karaf 
provides modulith runtime for the enterprise, running on premise or on cloud. 
Focus on your business code and applications, Apache Karaf deals with the 
rest.</subtitle></feed>
\ No newline at end of file

Added: karaf/site/production/security/cve-2026-91085.txt
==============================================================================
--- /dev/null   00:00:00 1970   (empty, because file is newly added)
+++ karaf/site/production/security/cve-2026-91085.txt   Mon Sep 28 16:08:00 
2026        (r1938619)
@@ -0,0 +1,52 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA256
+
+CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows 
privilege escalation to admin
+
+Severity: moderate 
+
+Affected versions:
+
+- - Apache Karaf before 4.4.12
+
+Description:
+
+Apache Karaf's shell/SSH command security is enforced by per-scope ACL 
configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). 
SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an 
invocation and, when no ACL rule matches the command, fails open: 
ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety 
valve for this, karaf.secured.command.compulsory.roles, ships commented out in 
etc/system.properties, so an unmatched command is allowed for any authenticated 
user.
+
+The shipped org.apache.karaf.command.acl.config ACL 
(assemblies/features/standard/src/main/feature/feature.xml, mirrored into 
instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. 
It restricts delete to admin, restricts edit/property-*/update on the 
jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* 
PIDs to admin, and allows manager for everything else, but config:install was 
simply unmatched, and therefore allowed for any authenticated user, including 
one holding only the viewer role.
+
+config:install <url> <finalname> fetches url and writes it into ${karaf.etc} 
as finalname. It calls PathUtils.checkWithin() to block .. traversal outside 
karaf.etc, but that folder holds every security-relevant file Karaf ships: 
users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* 
files, including the very ACL file that (mis)governs this command. With 
-o/--override, an existing file is overwritten with attacker-controlled bytes 
fetched from an arbitrary URL.
+
+Because felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix 
FileInstall also watches and reloads any .cfg file dropped there, closing the 
loop without requiring a restart.
+
+By contrast, bundle:install, feature:install and kar:install are all 
admin-only in their own ACLs, and config:delete is admin in this same ACL, 
config:install was the outlier.
+
+Mitigation
+
+Add install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the 
file is absent), and/or set karaf.secured.command.compulsory.roles=admin in 
etc/system.properties (and restart) to make unmatched commands fail closed by 
default.
+
+Credit:
+
+Rin Ray <[email protected]> (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-91085
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6jjMbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52dCIP/3zxXr4+H63MMYdCO+cu
+dkOAdiF86gz+y/8KbkvvHNvXiR2h/W8Cx7DDMXHswZhqHMTHC6U38pcumJeCOnWM
+IJvYMUYzNGz0ORsMv/BnitMIFGZ8e75GLpN6/w2G2mOeS85ibimj9HE/XzVIKL39
+GdWE2YwSGsFv7bW6lDEU1+OadiXei1P50Mq6JkRg2pLqTNn2yFS34RQlSlKtS1Vb
+Ucgahwx2RE45x0oB4m/ph3txlvbcj1vJOa2Mx0mfDSc3Bn93PTmsDrCR3pahPBHK
+5/YU4GV4FF+Y5LYQC397ZOlAW+6VVlqzA+nsRhHGKOsZoGbTqrLbSH206Xmdghr1
+G+GKMQYGnwsiHZT+u2c+HqTFgjufYj6lcgJNvaG4TYsBMtiwUYWap6ddpZIaUyV+
+o/UtcQNOiN1+GEMgud2vrtwkR4dQKdUjNWyT5fPywBbsIXPAapGo0xmwkP/KbASX
+v1euIFwWC7Azzl5OC2PdirnopjxZ6a3XuVX4olmbx8mcheixLmuLHB8btSx7rajS
+N4g7DPVbJCmIwNIkc3fyd6c/1UuHaBsx0juomd0KY/lybagLAW6xEZLklXApYofx
+c3DFfJbRyEjlFv62hKQva71nPFZG1O1JHZpvxvOYlTidUGiTXcJvHI3a27RYzATP
+OG9zW1Gybi56CgohRuJugNKb
+=7Z0Q
+-----END PGP SIGNATURE-----

Reply via email to