CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace
Authorization bypass through User-Controlled key vulnerability in Apache Camel K.
An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components.
This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.
Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Camel Kto a version that resolves this vulnerability.Fixed in 2.9.3 - Upgrade
Upgrade
Apache Camel Kto a version that resolves this vulnerability.Fixed in 2.10.2 - Upgrade
Upgrade
Apache Camel Kto a version that resolves this vulnerability.Fixed in 2.11.0
Event History
Frequently Asked Questions
Which deployments are affected?
Apache Camel K versions from 2.0.0 before 2.9.3 and from 2.10.1 before 2.10.2 are affected. The issue is fixed in 2.9.3, 2.10.2, and 2.11.0.
What does an attacker need to exploit this issue?
A tenant must be able to control custom resource resolution involving the Camel K Builder trait mavenProfiles ValueSources and reference a secret by name. The flaw permits resolution of tenant-named secrets in the operator namespace.
What information could be exposed?
An affected tenant may be able to reference and expose secrets belonging to other tenants or to operator components when those secrets are in the operator namespace.
What should teams do to remediate the issue?
Upgrade Apache Camel K to version 2.9.3, 2.10.2, or 2.11.0. These versions contain the fix.