https://seclists.org/oss-sec/2026/q3/970: CVE-2026-92142: Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
Published Sep 28, 2026
·Updated
Affected Software
1 affected component
Apache Karaf<4.4.12
Frequently Asked Questions
1
Who can exploit this issue?
Any user who can authenticate to the remote JMX endpoint can exploit it, including an account assigned only the least-privileged "viewer" role. The affected remote JMX connector uses the RMI registry/server on ports 1099 and 44444 by default.
2
Are role restrictions in the JMX ACL configuration effective against the affected operations?
No. The role checks configured in etc/jmx.acl.*.cfg are not applied to createMBean, registerMBean, or unregisterMBean, because those lifecycle operations are forwarded directly to the underlying MBeanServer.
3
What can an authenticated low-privilege JMX user do?
They can call createMBean() to instantiate an arbitrary class as an MBean. They can also use unregisterMBean() to remove that MBean afterward.
4
Which releases are affected?
Apache Karaf versions before 4.4.12 are affected.