Apache Karaf

7 known vulnerabilities in Apache Karaf, 2 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-92142 CVSS 8.8 high Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC) on MBean…
  • CVE-2026-91085 CVSS 6.3 medium Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg)…
  • CVE-2026-91048 CVSS 9.8 critical The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a…
  • CVE-2026-91012 CVSS 9.8 critical org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell…
  • CVE-2026-91006 CVSS 8.8 high Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string…
  • CVE-2026-90979 CVSS 7.3 high LDAPCache and LDAPBackingEngine build LDAP search filters for user lookup and role lookup by textually substituting the placeholders %u…
  • CVE-2026-92230 CVSS 7.5 high Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a…