-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 CVE-2026-91012: Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalation Severity: important Affected versions: - - Apache Karaf (org.apache.karaf.config.core.impl) before 4.4.12 Description: org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that the result stays inside ${karaf.etc}: * if the submitted property map contains a felix.fileinstall.filename entry, that value is turned directly into a File (getCfgFileFromProperty), so it can point to any absolute path the Karaf process can write to; * otherwise the configuration PID is concatenated verbatim into the target file name (generateConfigFilename(): new File(karaf.etc, pid + ".cfg")), so a PID containing ".." segments resolves outside ${karaf.etc}. createFactoryConfiguration() has the same issue via the factory PID/alias. Both code paths are reachable by any caller holding the "manager" role under Karaf's shipped command/JMX ACL (org.apache.karaf.command.acl.conf.cfg: "update = manager"). Such a user can therefore write attacker-controlled content to any file the Karaf process can write, including files the same ACL otherwise reserves to "admin" (etc/users.properties, etc/*.acl.*.cfg, etc/org.apache.karaf.management.cfg, and similar), allowing a manager-role user to grant themselves the admin role or otherwise take over the container. ConfigMBeanImpl.install() and the config:install shell command already guarded the equivalent risk on their own code path with a finalname.contains("..") string check, but that check does not stop absolute paths or symlink-based escapes, and it was never applied to ConfigRepositoryImpl.update() / createFactoryConfiguration() at all. Credit: n0mi1k (reporter) References: https://karaf.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-91012 -----BEGIN PGP SIGNATURE----- iQJPBAEBCAA5FiEEGqjPktQJpzOT0Lc2v/LuQsgoLnYFAmq6hrwbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMCwzAAoJEL/y7kLIKC52i5YP/17D5+5aLF0nlVld+QU2 QmhlL7QvkidS6SnLVj709f5lXqdlbM3NfNkxjNC3gWMblcVogAFa21QLgOOrPq0T K3EOpB/5vN0ak148NvUbrB9RhBHj1GlvWpwgsloO4LHgZHryAbGoXqI7/qzVyQhy 8MGPDwMvG8OYuTtDVaDDvWDlcu2nr1PuVBt5twmYfIEFS+3Gpmwp+uiI50EQh/Rq cJhA643XrKAf9+3SrmsxltqG7gtEnlwoDBeYRjJ+FNMSUNm2vX3RbhEY4Qsa5syk FGsBm+ish1DipWzQnSYL67uWMIzrywyIFEJU12dOQnvxcoNDYdhnXQGSnxSCnShE P9xJMYeyvpMPLy5AjGQ0XC9cy0RyGPForhe82fLmrYBcYL5vEwwOgt/9AqJ7+HeC tz0MuUFLUuMw7R+G7w6geN8HSv5arXfW3iK2X5hw9IK2X7dYrx52C+6hFxpCoy/E n7mz5MHxkltRoAPzO4RjYYZQRCZSxIpFXQ9TPW2zrk8uR3SuE0v/xsM8MXP7GKyp P45Aa3XCABHvAop8wOtCHYwH+7xaljUKck75qcmxpp4RiRA3UoSvxnkUGy96cm6h esCpo4MpbqEOa8O+7u8aIV3zX81fnBH6pjXQYaER7WMw3WQkvE5hs8nf9/1TcfO/ h2aXf0lM+O/QXhrKSWZaJ1Dv =LDcl -----END PGP SIGNATURE-----