CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod
Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K.
An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator.
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.
Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Camel Kto a version that resolves this vulnerability.Fixed in 2.9.3 - Upgrade
Upgrade
Apache Camel Kto a version that resolves this vulnerability.Fixed in 2.10.2 - Upgrade
Upgrade
Apache Camel Kto a version that resolves this vulnerability.Fixed in 2.11.0
Event History
Frequently Asked Questions
Who can exploit this issue, and where does the resulting code run?
A tenant able to control repository content can influence dynamically evaluated Maven configuration. Successful exploitation can execute arbitrary code inside the Camel K operator pod with the operator's privileges.
Which Camel K releases are affected?
Affected releases are 2.0.0 through versions before 2.9.3, and 2.10.1 through versions before 2.10.2. The issue is fixed in 2.9.3, 2.10.2, and 2.11.0.
What is the recommended remediation?
Upgrade Apache Camel K to 2.9.3, 2.10.2, or 2.11.0. The provided information does not identify a mitigation for environments that cannot immediately upgrade.