{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-91006","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2026-09-14T15:56:23.927Z","datePublished":"2026-09-28T10:44:32.652Z","dateUpdated":"2026-09-29T21:03:21.368Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2026-09-28T10:44:32.652Z"},"title":"Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)","problemTypes":[{"descriptions":[{"description":"CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')","lang":"en","cweId":"CWE-78","type":"CWE"}]}],"source":{"defect":["https://github.com/apache/karaf/pull/2878"],"advisory":"https://karaf.apache.org/security/cve-2026-91006.txt","discovery":"EXTERNAL"},"affected":[{"vendor":"Apache Software Foundation","product":"Apache Karaf","packageName":"org.apache.karaf:org.apache.karaf.instance.core","versions":[{"status":"affected","version":"0","lessThan":"4.4.12","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"value":"Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.\n\n\nReachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).\n\nMitigation   *  Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.\n  *  Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.\n  *  Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.","lang":"en","supportingMedia":[{"type":"text/html","base64":false,"value":"Apache Karaf's instance-management service (<code>InstanceServiceImpl</code>) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through&nbsp;<code>/bin/sh&nbsp;</code>(Unix) or&nbsp;<code>cscript</code>&nbsp;(Windows). The caller-supplied&nbsp;<code>javaOpts</code>&nbsp;value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (<code>;</code>,&nbsp;<code>|</code>,&nbsp;<code>`</code>,&nbsp;<code>$(...)</code>) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.<div><br></div><div>Reachable via the shell commands&nbsp;<code>instance:create</code>,&nbsp;<code>instance:start</code>,&nbsp;<code>instance:restart</code>,&nbsp;<code>instance:change-opts</code>, and the equivalent&nbsp;<code>InstanceMBean</code>&nbsp;JMX operations (<code>createInstance</code>,&nbsp;<code>startInstance</code>,&nbsp;<code>changeJavaOpts</code>,&nbsp;<code>cloneInstance</code>).</div><h3>Mitigation&nbsp;</h3><div><ul><li>Set&nbsp;<code>karaf.secured.command.compulsory.roles=admin</code>&nbsp;in&nbsp;<code>etc/system.properties</code>&nbsp;to close the fail-open gap for all unconfigured command scopes.</li><li>Restrict which principals can reach&nbsp;<code>instance:*</code>&nbsp;commands and&nbsp;<code>InstancesMBean</code>&nbsp;via&nbsp;<code>etc/users.properties</code>&nbsp;role assignments.</li><li>Treat&nbsp;<code>javaOpts</code>&nbsp;passed to i<code>nstance:create</code>/<code>instance:start</code>/<code>instance:change-opts</code>/<code>InstancesMBean</code>&nbsp;as untrusted input only from fully-trusted operators.</li></ul></div><div><br></div>"}]}],"references":[{"url":"https://lists.apache.org/thread/olzy0yjw82b20w59vonfjr1x7v5yzocr","tags":["vendor-advisory"]}],"metrics":[{"other":{"type":"Textual description of severity","content":{"text":"moderate"}},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"credits":[{"lang":"en","value":"n0mi1k <nomilksec@gmail.com>","type":"reporter"}],"x_generator":{"engine":"Vulnogram 1.0.3"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/28/3"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-09-28T13:10:12.951Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.8,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-09-29T03:55:20.472246Z","id":"CVE-2026-91006","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-29T21:03:21.368Z"}}]}}