{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-91048","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2026-09-14T17:14:08.734Z","datePublished":"2026-09-29T08:34:47.193Z","dateUpdated":"2026-10-01T14:13:30.717Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2026-09-29T08:34:47.193Z"},"title":"Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege escalation to remote code execution via jdbc:ds-create","problemTypes":[{"descriptions":[{"description":"CWE-862","lang":"en","cweId":"CWE-862","type":"CWE"}]}],"source":{"discovery":"EXTERNAL"},"affected":[{"vendor":"Apache Software Foundation","product":"Apache Karaf","versions":[{"status":"affected","version":"0","lessThan":"4.4.12","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"value":"The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run every jdbc:* command. jdbc:ds-create stores a fully attacker-controlled JDBC URL into a pax-jdbc-config factory Configuration with no validation. pax-jdbc-config reactively turns that into a live DataSource. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2 INIT=RUNSCRIPT), so a viewer-level shell user could reach arbitrary code execution, bypassing the admin-role gate that already protects shell:exec. This is a privilege-escalation-to-RCE chain, not merely an \"admin misconfiguration\".\n\n\nThe same applies to jms:* shell commands.","lang":"en","supportingMedia":[{"type":"text/html","base64":false,"value":"The&nbsp;<code>jdbc</code>&nbsp;shell command scope shipped no&nbsp;<code>org.apache.karaf.command.acl.jdbc.cfg</code>. Karaf's command guard (<code>SecuredSessionFactoryImpl</code>) treats a command with no matching ACL rule as <b>allowed</b>, so any authenticated shell session (including one holding only the&nbsp;<code>viewer</code>&nbsp;role) could run every&nbsp;<code>jdbc:*</code>&nbsp;command.&nbsp;<code>jdbc:ds-create</code>&nbsp;stores a fully attacker-controlled JDBC URL into a&nbsp;<code>pax-jdbc-config</code>&nbsp;factory&nbsp;<code>Configuration</code>&nbsp;with no validation.&nbsp;<code>pax-jdbc-config</code>&nbsp;reactively turns that into a live&nbsp;<code>DataSource</code>. Several JDBC drivers run code or SQL at connection time based on URL parameters (e.g. H2&nbsp;<code>INIT=RUNSCRIPT</code>), so a&nbsp;<code>viewer</code>-level shell user could reach arbitrary code execution, bypassing the&nbsp;<code>admin</code>-role gate that already protects&nbsp;<code>shell:exec</code>. This is a privilege-escalation-to-RCE chain, not merely an \"admin misconfiguration\".<div><br></div><div>The same applies to&nbsp;<code>jms:*</code>&nbsp;shell commands.</div>"}]}],"references":[{"url":"https://lists.apache.org/thread/ph3867mxh2tft75w0o1hpn10f5mbmw32","tags":["vendor-advisory"]}],"metrics":[{"other":{"type":"Textual description of severity","content":{"text":"moderate"}},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"credits":[{"lang":"en","value":"MopMonk-AI <mopmonk-ai@tophant.com>","type":"reporter"}],"x_generator":{"engine":"Vulnogram 1.0.3"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/28/9"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-09-29T09:15:44.666Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":9.8,"attackVector":"NETWORK","baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","integrityImpact":"HIGH","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-10-01T14:13:10.417139Z","id":"CVE-2026-91048","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-01T14:13:30.717Z"}}]}}