https://seclists.org/oss-sec/2026/q3/969: CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
Affected Software
Frequently Asked Questions
Which users can exploit this issue?
Any authenticated Apache Karaf shell or SSH user can reach the unmatched command under the shipped ACL configuration, including users with only the viewer role. The issue does not require the user to hold the admin or manager role.
What does an attacker need to do to exploit it?
The attacker needs authenticated access to the Karaf shell or SSH interface and must invoke config:install with a URL and final name. The command fetches content from the supplied URL and writes it using the specified final name.
Are default installations affected?
Yes. The shipped org.apache.karaf.command.acl.config ACL has no rule for config:install, and the karaf.secured.command.compulsory.roles safety setting is commented out in the shipped system.properties. As a result, an unmatched command is allowed by default for authenticated users.
How can I determine whether an instance is exposed?
Instances running Apache Karaf before 4.4.12 are affected. Inspect etc/org.apache.karaf.command.acl.config.cfg for an install ACL entry and check whether karaf.secured.command.compulsory.roles remains commented out in etc/system.properties.
What can be done if an immediate upgrade is not possible?
Restrict config:install in the config command ACL so it requires an appropriate privileged role, rather than leaving it unmatched. The safety setting karaf.secured.command.compulsory.roles should also not be left commented out, because unmatched commands otherwise pass the security check.