{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-91085","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2026-09-14T17:55:38.562Z","datePublished":"2026-09-29T08:39:33.209Z","dateUpdated":"2026-10-01T14:18:12.957Z"},"containers":{"cna":{"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2026-09-29T08:39:33.209Z"},"title":"Apache Karaf: config:install missing ACL entry allows privilege escalation to admin","problemTypes":[{"descriptions":[{"description":"CWE-862","lang":"en","cweId":"CWE-862","type":"CWE"}]}],"source":{"discovery":"EXTERNAL"},"affected":[{"vendor":"Apache Software Foundation","product":"Apache Karaf","versions":[{"status":"affected","version":"0","lessThan":"4.4.12","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"value":"Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule matches the command, fails open: ACLConfigurationParser.Specificity.NO_MATCH sets passCheck = true. The safety valve for this, karaf.secured.command.compulsory.roles, ships commented out in etc/system.properties, so an unmatched command is allowed for any authenticated user.\n\n\nThe shipped org.apache.karaf.command.acl.config ACL (assemblies/features/standard/src/main/feature/feature.xml, mirrored into instance/.../etc/org.apache.karaf.command.acl.config.cfg) has no install entry. It restricts delete to admin, restricts edit/property-*/update on the jmx.acl.*, org.apache.karaf.command.acl.* and org.apache.karaf.service.acl.* PIDs to admin, and allows manager for everything else, but config:install was simply unmatched, and therefore allowed for any authenticated user, including one holding only the viewer role.\n\n\n\n\nconfig:install <url> <finalname> fetches url and writes it into ${karaf.etc} as finalname. It calls PathUtils.checkWithin() to block .. traversal outside karaf.etc, but that folder holds every security-relevant file Karaf ships: users.properties, keys.properties, host.key, and all org.apache.karaf.*.acl.* files, including the very ACL file that (mis)governs this command. With -o/--override, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.\n\n\n\n\nBecause felix.fileinstall.dir = ${karaf.etc} (etc/config.properties), Felix FileInstall also watches and reloads any .cfg file dropped there, closing the loop without requiring a restart.\n\n\n\n\nBy contrast, bundle:install, feature:install and kar:install are all admin-only in their own ACLs, and config:delete is admin in this same ACL, config:install was the outlier.\n\nMitigationAdd install = admin in etc/org.apache.karaf.command.acl.config.cfg (create the file is absent), and/or set karaf.secured.command.compulsory.roles=admin in etc/system.properties (and restart) to make unmatched commands fail closed by default.","lang":"en","supportingMedia":[{"type":"text/html","base64":false,"value":"Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (<code>etc/org.apache.karaf.command.acl.&lt;scope&gt;.cfg</code>).&nbsp;<code>SecuredSessionFactoryImpl.checkSecurity()</code>&nbsp;resolves the roles required for an invocation and, when no ACL rule matches the command, <b>fails open</b>:&nbsp;<code>ACLConfigurationParser.Specificity.NO_MATCH</code>&nbsp;sets&nbsp;<code>passCheck = true</code>. The safety valve for this,&nbsp;<code>karaf.secured.command.compulsory.roles</code>, ships commented out in&nbsp;<code>etc/system.properties</code>, so an unmatched command is allowed for any authenticated user.<div><br></div><div>The shipped&nbsp;<code>org.apache.karaf.command.acl.config</code>&nbsp;ACL (<code>assemblies/features/standard/src/main/feature/feature.xml</code>, mirrored into&nbsp;<code>instance/.../etc/org.apache.karaf.command.acl.config.cfg</code>) has no&nbsp;<code>install</code>&nbsp;entry. It restricts&nbsp;<code>delete</code>&nbsp;to&nbsp;<code>admin</code>, restricts&nbsp;<code>edit</code>/<code>property-*</code>/<code>update</code>&nbsp;on the&nbsp;<code>jmx.acl.*</code>,&nbsp;<code>org.apache.karaf.command.acl.*</code>&nbsp;and&nbsp;<code>org.apache.karaf.service.acl.*</code>&nbsp;PIDs to&nbsp;<code>admin</code>, and allows&nbsp;<code>manager</code>&nbsp;for everything else, but&nbsp;<code>config:install</code>&nbsp;was simply unmatched, and therefore allowed for any authenticated user, including one holding only the&nbsp;<code>viewer</code>&nbsp;role.</div><div><br></div><div><span>config:install &lt;url&gt; &lt;finalname&gt;</span>&nbsp;fetches&nbsp;<code>url</code>&nbsp;and writes it into&nbsp;<code>${karaf.etc}</code>&nbsp;as&nbsp;<code>finalname</code>. It calls&nbsp;<code>PathUtils.checkWithin()</code>&nbsp;to block&nbsp;<code>..</code>&nbsp;traversal outside&nbsp;<code>karaf.etc</code>, but that folder holds every security-relevant file Karaf ships:&nbsp;<code>users.properties</code>,&nbsp;<code>keys.properties</code>,&nbsp;<code>host.key</code>, and all&nbsp;<code>org.apache.karaf.*.acl.*</code>&nbsp;files, including the very ACL file that (mis)governs this command. With&nbsp;<code>-o</code>/<code>--override</code>, an existing file is overwritten with attacker-controlled bytes fetched from an arbitrary URL.</div><div><br></div><div>Because&nbsp;<code>felix.fileinstall.dir = ${karaf.etc}</code>&nbsp;(<code>etc/config.properties</code>), Felix FileInstall also watches and reloads any&nbsp;<code>.cfg</code>&nbsp;file dropped there, closing the loop without requiring a restart.</div><div><br></div><div>By contrast,&nbsp;<code>bundle:install</code>,&nbsp;<code>feature:install</code>&nbsp;and&nbsp;<code>kar:install</code>&nbsp;are all&nbsp;<code>admin</code>-only in their own ACLs, and&nbsp;<code>config:delete</code>&nbsp;is&nbsp;<code>admin</code>&nbsp;in this same ACL,&nbsp;<code>config:install</code>&nbsp;was the outlier.</div><h3>Mitigation</h3><div>Add&nbsp;<code>install = admin</code>&nbsp;in&nbsp;<code>etc/org.apache.karaf.command.acl.config.cfg</code>&nbsp;(create the file is absent), and/or set&nbsp;<code>karaf.secured.command.compulsory.roles=admin</code>&nbsp;in&nbsp;<code>etc/system.properties</code>&nbsp;(and restart) to make unmatched commands fail closed by default.</div>"}]}],"references":[{"url":"https://karaf.apache.org/security/cve-2026-91085.txt","tags":["vendor-advisory"]}],"metrics":[{"other":{"type":"Textual description of severity","content":{"text":"moderate"}},"scenarios":[{"lang":"en","value":"GENERAL"}]}],"credits":[{"lang":"en","value":"Rin Ray <rindilray@gmail.com>","type":"reporter"}],"x_generator":{"engine":"Vulnogram 1.0.3"}},"adp":[{"title":"CVE Program Container","references":[{"url":"http://www.openwall.com/lists/oss-security/2026/09/28/10"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2026-09-29T09:15:47.789Z"}},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":6.3,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","integrityImpact":"LOW","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"LOW","privilegesRequired":"LOW","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2026-10-01T14:17:41.304608Z","id":"CVE-2026-91085","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-10-01T14:18:12.957Z"}}]}}