-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 CVE-2026-91006: Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean) Severity: moderate Affected versions: - - Apache Karaf (org.apache.karaf:org.apache.karaf.instance.core) before 4.4.12 Description: Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators. This issue is being tracked as https://github.com/apache/karaf/pull/2878 Credit: n0mi1k (reporter) References: https://karaf.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-91006 https://github.com/apache/karaf/pull/2878 -----BEGIN PGP SIGNATURE----- iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6MW0bFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52Y3MP/RKanIhBGaEY2ZMfdgSx yqwfM3VICAo7sfQozD0U9GV3zLPAQxO6OXpaKFjbck1qr5X8BIAwMWdUS3DaFvdK XETWmrXfL7GOGGN+lRTCPO+be/cQiEN9DFELlpYq/7TGH98QKEdvRhSwIG9leBjf 8FmeVo9uPYVs5JC3MAHDjWV25SbyF5RQ3gas40B+9rvzbNkzAhfQmP98TSROTIFL caA60jv0qaAfVVXiykELLMSqWp0xQNIhj3N5BQwPW71Zwn09TFFB5RMDvs5DzBAi hN5s77T13KHWJIQIY/iYHrdDLF3H6AD6c4xMzes+a0rxkZ4y2Y6nnZegbh4JsLV6 N0ZqefybEQRTC2HGgLt0YrE46JOyJRvNHdpNkmhFbb0eZL/KSsARGYzXTbiz9Olg S7ZWBP8ZCnvat6uAcahNXFxwik7IBO6d/kfZEEFaidq0BA1GAoPudlHBM9q3MJe2 EKGEFvIfCuAG6lWgFdAfO7F8Ra3+yqfcSLgFXYc+hhHE7ZVQEuRsjaHyOU3Mf4Q2 yeqSVdc9miAg+/mesd3q+VvqCOvjFg7p4KxKlou+Lq7femgK4/E1lxjZl8kdhW2+ N4ssj6yUqQxz2kLkQtFdIEseF0nOgzP1UMNAmnm0Lu4jlp2C7X8c9ntLDQYAUm1S Nl20y1+BhbqfU8vUpYMcLT0W =Em1Z -----END PGP SIGNATURE-----