{"api_version":"1","generated_at":"2026-10-01T02:09:22+00:00","cve":"CVE-2026-91085","urls":{"html":"https://cve.report/CVE-2026-91085","api":"https://cve.report/api/cve/CVE-2026-91085.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-91085","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-91085"},"summary":{"title":"Apache Karaf: config:install missing ACL entry allows privilege escalation to admin","description":"Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule matches the command, fails open: ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety valve for this, karaf.secured.command.compulsory.roles, ships commented out in etc/system.properties, so an unmatched command is allowed for any authenticated user.\n\n\nThe shipped org.apache.karaf.command.acl.config ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. It restricts delete to admin, restricts edit/property-*/update on the jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* PIDs to admin, and allows manager for everything else, but config:install was simply unmatched, and therefore allowed for any authenticated user, including one holding only the viewer role.\n\n\n\n\nconfig:install <url> <finalname> fetches url and writes it into ${karaf.etc} as finalname. It calls PathUtils.checkWithin() to block .. traversal outside karaf.etc, but that folder holds every security-relevant file Karaf ships: users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* files, including the very ACL file that (mis)governs this command. With -o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.\n\n\n\n\nBecause felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix FileInstall also watches and reloads any .cfg file dropped there, closing the loop without requiring a restart.\n\n\n\n\nBy contrast, bundle:install, feature:install and kar:install are all admin-only in their own ACLs, and config:delete is admin in this same ACL, config:install was the outlier.\n\nMitigationAdd install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the file is absent), and/or set karaf.secured.command.compulsory.roles=admin in etc/system.properties (and restart) to make unmatched commands fail closed by default.","state":"PUBLISHED","assigner":"apache","published_at":"2026-09-29 09:17:10","updated_at":"2026-09-29 14:56:12"},"problem_types":["CWE-862","CWE-862 CWE-862"],"metrics":[],"references":[{"url":"https://karaf.apache.org/security/cve-2026-91085.txt","name":"https://karaf.apache.org/security/cve-2026-91085.txt","refsource":"security@apache.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/09/28/10","name":"http://www.openwall.com/lists/oss-security/2026/09/28/10","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-91085","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91085","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Apache Software Foundation","product":"Apache Karaf","version":"affected 4.4.12 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Rin Ray <rindilray@gmail.com>","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"91085","cve":"CVE-2026-91085","epss":"0.001630000","percentile":"0.048850000","score_date":"2026-09-29","updated_at":"2026-09-30 00:11:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2026-09-29T09:15:47.789Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/28/10"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache Karaf","vendor":"Apache Software Foundation","versions":[{"lessThan":"4.4.12","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"reporter","value":"Rin Ray <rindilray@gmail.com>"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (<code>etc/org.apache.karaf.command.acl.&lt;scope&gt;.cfg</code>).&nbsp;<code>SecuredSessionFactoryImpl.checkSecurity()</code>&nbsp;resolves the roles required for an invocation and, when no ACL rule matches the command, <b>fails open</b>:&nbsp;<code>ACLConfigurationParser.Specificity.NO_MATCH</code>&nbsp;sets&nbsp;<code>passCheck = true</code>. The safety valve for this,&nbsp;<code>karaf.secured.command.compulsory.roles</code>, ships commented out in&nbsp;<code>etc/system.properties</code>, so an unmatched command is allowed for any authenticated user.<div><br></div><div>The shipped&nbsp;<code>org.apache.karaf.command.acl.config</code>&nbsp;ACL (<code>assemblies/features/standard/src/main/feature/feature.xml</code>, mirrored into&nbsp;<code>instance/.../etc/org.apache.karaf.command.acl.config.cfg</code>) has no&nbsp;<code>install</code>&nbsp;entry. It restricts&nbsp;<code>delete</code>&nbsp;to&nbsp;<code>admin</code>, restricts&nbsp;<code>edit</code>/<code>property-*</code>/<code>update</code>&nbsp;on the&nbsp;<code>jmx.acl.*</code>,&nbsp;<code>org.apache.karaf.command.acl.*</code>&nbsp;and&nbsp;<code>org.apache.karaf.service.acl.*</code>&nbsp;PIDs to&nbsp;<code>admin</code>, and allows&nbsp;<code>manager</code>&nbsp;for everything else, but&nbsp;<code>config:install</code>&nbsp;was simply unmatched, and therefore allowed for any authenticated user, including one holding only the&nbsp;<code>viewer</code>&nbsp;role.</div><div><br></div><div><span>config:install &lt;url&gt; &lt;finalname&gt;</span>&nbsp;fetches&nbsp;<code>url</code>&nbsp;and writes it into&nbsp;<code>${karaf.etc}</code>&nbsp;as&nbsp;<code>finalname</code>. It calls&nbsp;<code>PathUtils.checkWithin()</code>&nbsp;to block&nbsp;<code>..</code>&nbsp;traversal outside&nbsp;<code>karaf.etc</code>, but that folder holds every security-relevant file Karaf ships:&nbsp;<code>users.properties</code>,&nbsp;<code>keys.properties</code>,&nbsp;<code>host.key</code>, and all&nbsp;<code>org.apache.karaf.*.acl.*</code>&nbsp;files, including the very ACL file that (mis)governs this command. With&nbsp;<code>-o</code>/<code>--override</code>, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.</div><div><br></div><div>Because&nbsp;<code>felix.fileinstall.dir = ${karaf.etc}</code>&nbsp;(<code>etc/config.properties</code>), Felix FileInstall also watches and reloads any&nbsp;<code>.cfg</code>&nbsp;file dropped there, closing the loop without requiring a restart.</div><div><br></div><div>By contrast,&nbsp;<code>bundle:install</code>,&nbsp;<code>feature:install</code>&nbsp;and&nbsp;<code>kar:install</code>&nbsp;are all&nbsp;<code>admin</code>-only in their own ACLs, and&nbsp;<code>config:delete</code>&nbsp;is&nbsp;<code>admin</code>&nbsp;in this same ACL,&nbsp;<code>config:install</code>&nbsp;was the outlier.</div><h3>Mitigation</h3><div>Add&nbsp;<code>install = admin</code>&nbsp;in&nbsp;<code>etc/org.apache.karaf.command.acl.config.cfg</code>&nbsp;(create the file is absent), and/or set&nbsp;<code>karaf.secured.command.compulsory.roles=admin</code>&nbsp;in&nbsp;<code>etc/system.properties</code>&nbsp;(and restart) to make unmatched commands fail closed by default.</div>"}],"value":"Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule matches the command, fails open: ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety valve for this, karaf.secured.command.compulsory.roles, ships commented out in etc/system.properties, so an unmatched command is allowed for any authenticated user.\n\n\nThe shipped org.apache.karaf.command.acl.config ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. It restricts delete to admin, restricts edit/property-*/update on the jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* PIDs to admin, and allows manager for everything else, but config:install was simply unmatched, and therefore allowed for any authenticated user, including one holding only the viewer role.\n\n\n\n\nconfig:install <url> <finalname> fetches url and writes it into ${karaf.etc} as finalname. It calls PathUtils.checkWithin() to block .. traversal outside karaf.etc, but that folder holds every security-relevant file Karaf ships: users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* files, including the very ACL file that (mis)governs this command. With -o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.\n\n\n\n\nBecause felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix FileInstall also watches and reloads any .cfg file dropped there, closing the loop without requiring a restart.\n\n\n\n\nBy contrast, bundle:install, feature:install and kar:install are all admin-only in their own ACLs, and config:delete is admin in this same ACL, config:install was the outlier.\n\nMitigationAdd install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the file is absent), and/or set karaf.secured.command.compulsory.roles=admin in etc/system.properties (and restart) to make unmatched commands fail closed by default."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-29T08:39:33.209Z","orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache"},"references":[{"tags":["vendor-advisory"],"url":"https://karaf.apache.org/security/cve-2026-91085.txt"}],"source":{"discovery":"EXTERNAL"},"title":"Apache Karaf: config:install missing ACL entry allows privilege escalation to admin","x_generator":{"engine":"Vulnogram 1.0.3"}}},"cveMetadata":{"assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","assignerShortName":"apache","cveId":"CVE-2026-91085","datePublished":"2026-09-29T08:39:33.209Z","dateReserved":"2026-09-14T17:55:38.562Z","dateUpdated":"2026-09-29T09:15:47.789Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-29 09:17:10","lastModifiedDate":"2026-09-29 14:56:12","problem_types":["CWE-862","CWE-862 CWE-862"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"91085","Ordinal":"1","Title":"Apache Karaf: config:install missing ACL entry allows privilege ","CVE":"CVE-2026-91085","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"91085","Ordinal":"1","NoteData":"Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule matches the command, fails open: ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety valve for this, karaf.secured.command.compulsory.roles, ships commented out in etc/system.properties, so an unmatched command is allowed for any authenticated user.\n\n\nThe shipped org.apache.karaf.command.acl.config ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. It restricts delete to admin, restricts edit/property-*/update on the jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* PIDs to admin, and allows manager for everything else, but config:install was simply unmatched, and therefore allowed for any authenticated user, including one holding only the viewer role.\n\n\n\n\nconfig:install <url> <finalname> fetches url and writes it into ${karaf.etc} as finalname. It calls PathUtils.checkWithin() to block .. traversal outside karaf.etc, but that folder holds every security-relevant file Karaf ships: users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* files, including the very ACL file that (mis)governs this command. With -o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.\n\n\n\n\nBecause felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix FileInstall also watches and reloads any .cfg file dropped there, closing the loop without requiring a restart.\n\n\n\n\nBy contrast, bundle:install, feature:install and kar:install are all admin-only in their own ACLs, and config:delete is admin in this same ACL, config:install was the outlier.\n\nMitigationAdd install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the file is absent), and/or set karaf.secured.command.compulsory.roles=admin in etc/system.properties (and restart) to make unmatched commands fail closed by default.","Type":"Description","Title":"Apache Karaf: config:install missing ACL entry allows privilege "}]}}}