CVE-2026-80352
9.8Apache Software Foundation · Apache Camel K
Apache Camel K is susceptible to a YAML injection vulnerability in custom resource configuration, allowing unauthorized Kubernetes object creation with operator privileges.
Executive summary
A critical YAML injection vulnerability in Apache Camel K allows attackers to perform unauthorized operations within the Kubernetes environment, necessitating an immediate software update.
Vulnerability
This is a code injection flaw (CWE-94) where improper control of custom resource configuration allows an attacker to inject arbitrary Kubernetes objects. The vulnerability is exploitable by an authorized custom resource author, granting them the ability to execute unauthorized actions with the privileges of the Camel K operator.
Business impact
The vulnerability carries a CVSS score of 9.8, indicating a critical severity level due to the potential for total compromise of the affected environment. Successful exploitation could lead to privilege escalation within the Kubernetes cluster, unauthorized access to sensitive data, or complete system disruption. Such an incident presents significant risks to business operations, including potential data exfiltration and loss of infrastructure control.
Remediation
Immediate Action: Upgrade Apache Camel K to version 2.9.3, 2.10.2, or 2.11.0 to incorporate the necessary security patches.
Proactive Monitoring: Monitor Kubernetes audit logs for suspicious custom resource definitions or unexpected object creation patterns originating from unauthorized or unusual service accounts.
Compensating Controls: Implement strict Role-Based Access Control (RBAC) policies to limit who can create or modify custom resources within the cluster, effectively reducing the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical CVSS score and the potential for full operator-level privilege escalation, administrators must prioritize this update as part of their immediate maintenance cycle. Organizations should verify their current deployment versions and apply the recommended patches to prevent potential infrastructure compromise.
More Apache Software Foundation CVEs
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written
- Published in the daily brief critical section