Apache Karaf

Apache · 16 CVEs

CVE-2026-92142
HIGH

Apache Karaf: Authorization bypass in JMX MBean lifecycle operations

Sep 29, 2026

CVE-2026-91085
MEDIUM

Apache Karaf: config:install missing ACL entry allows privilege escalation to admin

Sep 29, 2026

CVE-2026-91048
CRITICAL

Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execut…

Sep 29, 2026

CVE-2026-91012
CRITICAL

Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation

Sep 29, 2026

CVE-2026-91006
HIGH

Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)

Sep 28, 2026

CVE-2026-90979
HIGH

Apache Karaf: LDAP filter injection in JAAS LDAP login modules

Sep 28, 2026

CVE-2026-92230
HIGH

Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching

Sep 17, 2026

CVE-2026-24656
LOW

Apache Karaf: Decanter log-socket collector has deserialization vulnerability

Jan 26, 2026

CVE-2022-40145
CRITICAL

Apache Karaf: JDBC JAAS LDAP injection

Dec 21, 2022

CVE-2022-22932
MEDIUM

Path traversal flaws

Jan 26, 2022

CVE-2021-41766
HIGH

Insecure Java Deserialization in Apache Karaf

Jan 26, 2022

CVE-2019-0191
MEDIUM

karaf: Zip-slip vulnerability via kar file

Mar 20, 2019

CVE-2018-11788
CRITICAL

karaf: XML external entity processing

Jan 7, 2019

CVE-2018-11787
CRITICAL

karaf: Authentication bypass access to Gogo shell in the webconsole

Sep 18, 2018

CVE-2018-11786
HIGH

karaf: SSH RBAC security enforcement

Sep 18, 2018

CVE-2016-8750
HIGH

karaf: LDAP injection in LDAPLoginModule

Feb 19, 2018

Showing 1 to 16 of 16 CVEs