Skip to content
VulniPulse
Advisory severityHigh8.8Apache Software Foundation

High [CVE-2026-91006] Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows)

This high-severity Apache Software Foundation advisory covers CVE-2026-91006; related products: Apache Karaf.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-91006 Source published Source updated

VulniPulse record published Record updated

Related products & platforms
Apache Software FoundationUnclassified
Open source advisory

Android app · Google Play

Monitor future Apache Software Foundation CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted.

A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.

Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).

Mitigation * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.

  • Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.
  • Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.
Affected versions
  • Apache Karaf before 4.4.12

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Fixed versions
  • 4.4.12

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Mitigation checklist

Temporary workarounds
  • Mitigation * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.

Official advisory · high-confidence parse· fetched 8 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.