OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-91006

HIGH · CVSS 8.8 EPSS 0.90%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects Apache Karaf's instance-management service, which improperly handles user-supplied `javaOpts` values, allowing attackers to inject shell metacharacters and execute arbitrary OS commands as the Karaf process user. This poses a significant risk for systems running Windows, Apache, or Java, especially if the instance-management commands are accessible to untrusted users. Organizations utilizing Apache Karaf should prioritize remediation by implementing the recommended mitigations to restrict access and treat input as untrusted.

CVE
CVE-2026-91006
Severity
HIGH
CVSS
8.8
EPSS
0.90%
Windows Apache Java

Original NVD Description

Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation  * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.