Apache Karaf
Apache · 16 CVEs
Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
Sep 29, 2026
Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
Sep 29, 2026
Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execut…
Sep 29, 2026
Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation
Sep 29, 2026
Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
Sep 28, 2026
Apache Karaf: LDAP filter injection in JAAS LDAP login modules
Sep 28, 2026
Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching
Sep 17, 2026
Apache Karaf: Decanter log-socket collector has deserialization vulnerability
Jan 26, 2026
Apache Karaf: JDBC JAAS LDAP injection
Dec 21, 2022
Path traversal flaws
Jan 26, 2022
Insecure Java Deserialization in Apache Karaf
Jan 26, 2022
karaf: Zip-slip vulnerability via kar file
Mar 20, 2019
karaf: XML external entity processing
Jan 7, 2019
karaf: Authentication bypass access to Gogo shell in the webconsole
Sep 18, 2018
karaf: SSH RBAC security enforcement
Sep 18, 2018
karaf: LDAP injection in LDAPLoginModule
Feb 19, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-92142 | Apache Karaf: Authorization bypass in JMX MBean lifecycle operations | HIGH | 0.52% | Sep 29, 2026 |
| CVE-2026-91085 | Apache Karaf: config:install missing ACL entry allows privilege escalation to admin | MEDIUM | 0.20% | Sep 29, 2026 |
| CVE-2026-91048 | Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create | CRITICAL | 0.44% | Sep 29, 2026 |
| CVE-2026-91012 | Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation | CRITICAL | 0.45% | Sep 29, 2026 |
| CVE-2026-91006 | Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean) | HIGH | 0.90% | Sep 28, 2026 |
| CVE-2026-90979 | Apache Karaf: LDAP filter injection in JAAS LDAP login modules | HIGH | 0.27% | Sep 28, 2026 |
| CVE-2026-92230 | Apache Karaf: Improper release of ClassLoader references via static ThreadLocal caching | HIGH | 0.49% | Sep 17, 2026 |
| CVE-2026-24656 | Apache Karaf: Decanter log-socket collector has deserialization vulnerability | LOW | 0.73% | Jan 26, 2026 |
| CVE-2022-40145 | Apache Karaf: JDBC JAAS LDAP injection | CRITICAL | 2.50% | Dec 21, 2022 |
| CVE-2022-22932 | Path traversal flaws | MEDIUM | 2.75% | Jan 26, 2022 |
| CVE-2021-41766 | Insecure Java Deserialization in Apache Karaf | HIGH | 2.03% | Jan 26, 2022 |
| CVE-2019-0191 | karaf: Zip-slip vulnerability via kar file | MEDIUM | 4.86% | Mar 20, 2019 |
| CVE-2018-11788 | karaf: XML external entity processing | CRITICAL | 7.35% | Jan 7, 2019 |
| CVE-2018-11787 | karaf: Authentication bypass access to Gogo shell in the webconsole | CRITICAL | 2.57% | Sep 18, 2018 |
| CVE-2018-11786 | karaf: SSH RBAC security enforcement | HIGH | 1.90% | Sep 18, 2018 |
| CVE-2016-8750 | karaf: LDAP injection in LDAPLoginModule | HIGH | 5.18% | Feb 19, 2018 |
Showing 1 to 16 of 16 CVEs