{"api_version":"1","generated_at":"2026-10-01T03:14:20+00:00","cve":"CVE-2026-91012","urls":{"html":"https://cve.report/CVE-2026-91012","api":"https://cve.report/api/cve/CVE-2026-91012.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-91012","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-91012"},"summary":{"title":"Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation","description":"org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),\nwhich backs the \"config\" MBean and the config:* shell commands, derives the file\nit writes a configuration to from caller-supplied input without checking that\nthe result stays inside ${karaf.etc}:\n\n  *  if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;\n  *  otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + \".cfg\")), so a PID containing \"..\" segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias.\n\n\nBoth code paths are reachable by any caller holding the \"manager\" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: \"update = manager\"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to \"admin\" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.\n\n\n\n\n\n\nConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains(\"..\") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all.","state":"PUBLISHED","assigner":"apache","published_at":"2026-09-29 09:17:09","updated_at":"2026-09-29 14:56:12"},"problem_types":[],"metrics":[],"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/28/8","name":"http://www.openwall.com/lists/oss-security/2026/09/28/8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.apache.org/thread/op8trtz1qxkdwj2rjozhd9yt2yd6nhw4","name":"https://lists.apache.org/thread/op8trtz1qxkdwj2rjozhd9yt2yd6nhw4","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-91012","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91012","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Karaf","version":"affected 4.4.12 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"n0mi1k <nomilksec@gmail.com>","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"91012","cve":"CVE-2026-91012","epss":"0.001720000","percentile":"0.058710000","score_date":"2026-09-29","updated_at":"2026-09-30 00:11:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-09-29T09:15:41.656Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/28/8"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","packageName":"org.apache.karaf.config.core.impl","product":"Apache Karaf","vendor":"Apache Software Foundation","versions":[{"lessThan":"4.4.12","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"n0mi1k <nomilksec@gmail.com>"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<div><span>org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties)</span>,\nwhich backs the \"config\" MBean and the config:* shell commands, derives the file\nit writes a configuration to from caller-supplied input without checking that\nthe result stays inside&nbsp;<code>${karaf.etc}</code>:</div><div><ul><li>if the submitted property map contains a&nbsp;<code>felix.fileinstall.filename</code>&nbsp;entry, that value is turned directly into a&nbsp;<code>File</code>&nbsp;(<code>getCfgFileFromProperty</code>), so it can point to any absolute path the Karaf process can write to;</li><li>otherwise the configuration PID is concatenated verbatim into the target file name (<code>generateConfigFilename(): new File(karaf.etc, pid + \".cfg\")</code>), so a PID containing \"..\" segments resolves outside&nbsp;<code>${karaf.etc}</code>.&nbsp;<code>createFactoryConfiguration()</code>&nbsp;has the same issue via the factory PID/alias.</li></ul><div>Both code paths are reachable by any caller holding the \"manager\" role under Karaf's shipped command/JMX ACL (<code>org.apache.karaf.command.acl.conf.cfg:</code>&nbsp;\"<code>update = manager</code>\"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to \"<code>admin</code>\" (<code>etc/users.properties</code>,&nbsp;<code>etc/*.acl.*.cfg</code>,&nbsp;<code>etc/org.apache.karaf.management.cfg</code>, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.</div></div><div><br></div><div><span>ConfigMBeanImpl.install()</span>&nbsp;and the&nbsp;<code>config:install</code>&nbsp;shell command already guarded the equivalent risk on their own code path with a&nbsp;<code>finalname.contains(\"..\")</code>&nbsp;string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to&nbsp;<code>ConfigRepositoryImpl.update()</code>&nbsp;/&nbsp;<code>createFactoryConfiguration()</code>&nbsp;at all.</div>"}],"value":"org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),\nwhich backs the \"config\" MBean and the config:* shell commands, derives the file\nit writes a configuration to from caller-supplied input without checking that\nthe result stays inside ${karaf.etc}:\n\n  *  if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;\n  *  otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + \".cfg\")), so a PID containing \"..\" segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias.\n\n\nBoth code paths are reachable by any caller holding the \"manager\" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: \"update = manager\"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to \"admin\" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.\n\n\n\n\n\n\nConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains(\"..\") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all."}],"metrics":[{"other":{"content":{"text":"important"},"type":"Textual description of severity"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"providerMetadata":{"dateUpdated":"2026-09-29T08:34:11.409Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/op8trtz1qxkdwj2rjozhd9yt2yd6nhw4"}],"source":{"discovery":"EXTERNAL"},"title":"Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation","x_generator":{"engine":"Vulnogram 1.0.3"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-91012","datePublished":"2026-09-29T08:34:11.409Z","dateReserved":"2026-09-14T16:27:00.736Z","dateUpdated":"2026-09-29T09:15:41.656Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-29 09:17:09","lastModifiedDate":"2026-09-29 14:56:12","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"91012","Ordinal":"1","Title":"Apache Karaf: Path Traversal in Config Service Allows Manager-to","CVE":"CVE-2026-91012","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"91012","Ordinal":"1","NoteData":"org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties),\nwhich backs the \"config\" MBean and the config:* shell commands, derives the file\nit writes a configuration to from caller-supplied input without checking that\nthe result stays inside ${karaf.etc}:\n\n  *  if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to;\n  *  otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + \".cfg\")), so a PID containing \"..\" segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias.\n\n\nBoth code paths are reachable by any caller holding the \"manager\" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: \"update = manager\"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to \"admin\" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container.\n\n\n\n\n\n\nConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains(\"..\") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all.","Type":"Description","Title":"Apache Karaf: Path Traversal in Config Service Allows Manager-to"}]}}}