Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).
Mitigation * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.
* Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.
* Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 28 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache karaf |
|
| Vendors & Products |
Apache
Apache karaf |
Mon, 28 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators. | |
| Title | Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean) | |
| Weaknesses | CWE-78 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-09-28T13:10:12.951Z
Reserved: 2026-09-14T15:56:23.927Z
Link: CVE-2026-91006
No data.
Status : Received
Published: 2026-09-28T11:16:48.200
Modified: 2026-09-28T14:17:22.283
Link: CVE-2026-91006
No data.
OpenCVE Enrichment
Updated: 2026-09-28T13:00:15Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')