CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)

Published Sep 28, 2026
·
Updated

Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, , $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.

Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).

Mitigation  Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. Restrict which principals can reach instance: commands and InstancesMBean via etc/users.properties role assignments. Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.

Affected Software

1 affected component
Apache Karaf

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Restrict which principals can reach instance:* commands and the equivalent InstancesMBean JMX operations through role assignments in etc/users.properties.

    Apache Karaf instance-management commands and InstancesMBean role assignments in etc/users.properties = Restrict access to instance:* commands and InstancesMBean operations to authorized principals
  2. Configuration

    Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for unconfigured command scopes.

    Apache Karaf karaf.secured.command.compulsory.roles = admin
  3. Compensating control

    Treat javaOpts supplied to instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstancesMBean operations as untrusted input; allow these values only from fully trusted operators.

Event History

Sep 28, 2026
CVE Published
via MITRE·10:44 AM
Data Sourced
via MITRE·10:44 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any principal that can invoke the affected instance:* commands or equivalent InstancesMBean JMX operations and supply a javaOpts value can exploit it. The resulting command runs with the privileges of the Karaf process user.

2

Are default command authorization settings sufficient?

No. The mitigation notes a fail-open gap for unconfigured command scopes. Set karaf.secured.command.compulsory.roles=admin in etc/system.properties and restrict roles assigned access to instance:* commands and InstancesMBean.

3

Which operations should be restricted while remediation is pending?

Restrict access to instance:create, instance:start, instance:restart, and instance:change-opts, as well as InstancesMBean operations createInstance, startInstance, changeJavaOpts, and cloneInstance. Only fully trusted operators should be allowed to provide javaOpts values.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203