Author: jbonofre
Date: Mon Sep 28 16:08:00 2026
New Revision: 1938619
Log:
[scm-publish] Updating main website contents
Added:
karaf/site/production/security/cve-2026-91085.txt
Modified:
karaf/site/production/documentation.html
karaf/site/production/feed.xml
Modified: karaf/site/production/documentation.html
==============================================================================
--- karaf/site/production/documentation.html Mon Sep 28 15:51:59 2026
(r1938618)
+++ karaf/site/production/documentation.html Mon Sep 28 16:08:00 2026
(r1938619)
@@ -370,6 +370,13 @@
<div class="k-admonition">
<div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
<div>
+ <p>CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows
privilege escalation to admin</p>
+ <a class="btn btn-outline-primary btn-sm"
href="/security/cve-2026-91085.txt">Notes »</a>
+ </div>
+ </div>
+ <div class="k-admonition">
+ <div class="k-admonition-icon"><i class="fas fa-shield-halved"></i></div>
+ <div>
<p>CVE-2026-92230: Apache Karaf: Improper release of ClassLoader
references via static ThreadLocal caching</p>
<a class="btn btn-outline-primary btn-sm"
href="/security/cve-2026-92230.txt">Notes »</a>
</div>
Modified: karaf/site/production/feed.xml
==============================================================================
--- karaf/site/production/feed.xml Mon Sep 28 15:51:59 2026
(r1938618)
+++ karaf/site/production/feed.xml Mon Sep 28 16:08:00 2026
(r1938619)
@@ -1 +1 @@
-<?xml version="1.0" encoding="utf-8"?><feed
xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/"
version="4.4.1">Jekyll</generator><link
href="https://karaf.apache.org/feed.xml" rel="self" type="application/atom+xml"
/><link href="https://karaf.apache.org/" rel="alternate" type="text/html"
/><updated>2026-09-28T10:51:17-05:00</updated><id>https://karaf.apache.org/feed.xml</id><title
type="html">Apache Karaf - The modulith runtime</title><subtitle>Karaf
provides modulith runtime for the enterprise, running on premise or on cloud.
Focus on your business code and applications, Apache Karaf deals with the
rest.</subtitle></feed>
\ No newline at end of file
+<?xml version="1.0" encoding="utf-8"?><feed
xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/"
version="4.4.1">Jekyll</generator><link
href="https://karaf.apache.org/feed.xml" rel="self" type="application/atom+xml"
/><link href="https://karaf.apache.org/" rel="alternate" type="text/html"
/><updated>2026-09-28T11:07:18-05:00</updated><id>https://karaf.apache.org/feed.xml</id><title
type="html">Apache Karaf - The modulith runtime</title><subtitle>Karaf
provides modulith runtime for the enterprise, running on premise or on cloud.
Focus on your business code and applications, Apache Karaf deals with the
rest.</subtitle></feed>
\ No newline at end of file
Added: karaf/site/production/security/cve-2026-91085.txt
==============================================================================
--- /dev/null 00:00:00 1970 (empty, because file is newly added)
+++ karaf/site/production/security/cve-2026-91085.txt Mon Sep 28 16:08:00
2026 (r1938619)
@@ -0,0 +1,52 @@
+-----BEGIN PGP SIGNED MESSAGE-----
+Hash: SHA256
+
+CVE-2026-91085: Apache Karaf: config:install missing ACL entry allows
privilege escalation to admin
+
+Severity: moderate
+
+Affected versions:
+
+- - Apache Karaf before 4.4.12
+
+Description:
+
+Apache Karaf's shell/SSH command security is enforced by per-scope ACL
configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg).
SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an
invocation and, when no ACL rule matches the command, fails open:
ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety
valve for this, karaf.secured.command.compulsory.roles, ships commented out in
etc/system.properties, so an unmatched command is allowed for any authenticated
user.
+
+The shipped org.apache.karaf.command.acl.config ACL
(assemblies/features/standard/src/main/feature/feature.xml, mirrored into
instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry.
It restricts delete to admin, restricts edit/property-*/update on the
jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.*
PIDs to admin, and allows manager for everything else, but config:install was
simply unmatched, and therefore allowed for any authenticated user, including
one holding only the viewer role.
+
+config:install <url> <finalname> fetches url and writes it into ${karaf.etc}
as finalname. It calls PathUtils.checkWithin() to block .. traversal outside
karaf.etc, but that folder holds every security-relevant file Karaf ships:
users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.*
files, including the very ACL file that (mis)governs this command. With
-o/--override, an existing file is overwritten with attacker-controlled bytes
fetched from an arbitrary URL.
+
+Because felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix
FileInstall also watches and reloads any .cfg file dropped there, closing the
loop without requiring a restart.
+
+By contrast, bundle:install, feature:install and kar:install are all
admin-only in their own ACLs, and config:delete is admin in this same ACL,
config:install was the outlier.
+
+Mitigation
+
+Add install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the
file is absent), and/or set karaf.secured.command.compulsory.roles=admin in
etc/system.properties (and restart) to make unmatched commands fail closed by
default.
+
+Credit:
+
+Rin Ray <[email protected]> (reporter)
+
+References:
+
+https://karaf.apache.org/
+https://www.cve.org/CVERecord?id=CVE-2026-91085
+-----BEGIN PGP SIGNATURE-----
+
+iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6jjMbFIAAAAAABAAO
+bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52dCIP/3zxXr4+H63MMYdCO+cu
+dkOAdiF86gz+y/8KbkvvHNvXiR2h/W8Cx7DDMXHswZhqHMTHC6U38pcumJeCOnWM
+IJvYMUYzNGz0ORsMv/BnitMIFGZ8e75GLpN6/w2G2mOeS85ibimj9HE/XzVIKL39
+GdWE2YwSGsFv7bW6lDEU1+OadiXei1P50Mq6JkRg2pLqTNn2yFS34RQlSlKtS1Vb
+Ucgahwx2RE45x0oB4m/ph3txlvbcj1vJOa2Mx0mfDSc3Bn93PTmsDrCR3pahPBHK
+5/YU4GV4FF+Y5LYQC397ZOlAW+6VVlqzA+nsRhHGKOsZoGbTqrLbSH206Xmdghr1
+G+GKMQYGnwsiHZT+u2c+HqTFgjufYj6lcgJNvaG4TYsBMtiwUYWap6ddpZIaUyV+
+o/UtcQNOiN1+GEMgud2vrtwkR4dQKdUjNWyT5fPywBbsIXPAapGo0xmwkP/KbASX
+v1euIFwWC7Azzl5OC2PdirnopjxZ6a3XuVX4olmbx8mcheixLmuLHB8btSx7rajS
+N4g7DPVbJCmIwNIkc3fyd6c/1UuHaBsx0juomd0KY/lybagLAW6xEZLklXApYofx
+c3DFfJbRyEjlFv62hKQva71nPFZG1O1JHZpvxvOYlTidUGiTXcJvHI3a27RYzATP
+OG9zW1Gybi56CgohRuJugNKb
+=7Z0Q
+-----END PGP SIGNATURE-----