Back

CRITICAL

Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects

Published Sep 10, 2026

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.

A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator.

This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2.

Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 10, 2026
Updated Sep 10, 2026
Reserved Aug 26, 2026
CISA Vulnrichment
Updated Sep 10, 2026
NVD
Status Analyzed
Modified Sep 14, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner apache
Published Sep 10, 2026
Updated Sep 10, 2026
Exploited since n/a
EUVD-2026-75290