OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-91048

CRITICAL · CVSS 9.8 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Apache Karaf environment is vulnerable due to the absence of an access control list for the `jdbc` shell command, allowing any authenticated user, even those with minimal permissions, to execute potentially harmful `jdbc:*` commands. This misconfiguration enables a privilege escalation to remote code execution (RCE) through the manipulation of JDBC URLs, which can execute arbitrary code upon connection. Organizations using Apache Karaf should prioritize addressing this vulnerability to protect against unauthorized access and potential exploitation by low-privilege users.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-91048
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%
Apache

Original NVD Description

The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an "admin misconfiguration". The same applies to jms:* shell commands.