CVE-2026-80351

9.8

Apache Software Foundation · Apache Camel K

An eval injection vulnerability in Apache Camel K allows unauthenticated tenants to execute arbitrary code within the operator pod via malicious Maven configurations.

Executive summary

A critical eval injection vulnerability in Apache Camel K allows unauthenticated attackers to execute arbitrary code with operator privileges, posing a severe risk to containerized environments.

Vulnerability

This is an eval injection flaw (CWE-95) where improper neutralization of directives in dynamically evaluated Maven configuration enables unauthenticated users to influence code execution within the operator pod.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code with the full privileges of the Camel K operator. Given the CVSS score of 9.8, this represents a critical risk that could lead to complete compromise of the operator pod, unauthorized access to sensitive data, and potential lateral movement within the Kubernetes cluster.

Remediation

Immediate Action: Upgrade Apache Camel K to version 2.9.3, 2.10.2, or 2.11.0 immediately to apply the necessary security patches.

Proactive Monitoring: Monitor operator pod logs for unexpected Maven configuration activity or unauthorized execution patterns that deviate from standard deployment behavior.

Compensating Controls: Implement strict network policies and admission controllers to restrict the ability of untrusted tenants to influence operator configurations or interact with sensitive Kubernetes APIs.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates an immediate response. Organizations utilizing Apache Camel K must prioritize patching their instances to the specified secure versions to eliminate the risk of remote code execution. Failure to address this flaw could result in a total compromise of the affected operator environment.

More Apache Software Foundation CVEs

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section

Sources