Junglewise Threat Intelligence

CVE-2026-40022: Apache Camel authentication bypass in camel-platform-http-main

CVE-2026-40022 · Severity: high · CVSS 8.2 · Published 2026-04-27

Technologies: Red Hat build of Apache Camel for Spring Boot. Vendors: Red Hat, Apache Software Foundation.

Executive brief

Apache Camel, a popular integration framework, contains a security flaw in its embedded web and management servers. When specific security settings are enabled, the system fails to properly protect sub-pages (subpaths) of the main application or management interface. This allows unauthorized individuals to bypass login requirements and access sensitive business data or internal system information, such as process IDs and operating system details.

Technical details

An authentication bypass exists in Apache Camel's camel-platform-http-main component due to incorrect path matching in the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes. When a non-root context path (e.g., /api) is configured without an explicit authentication path, the authentication handler only applies to the exact path rather than its subpaths. This occurs because the Vert.x sub-router mounting model registers the handler at the resolved path inside a sub-router mounted at the base path. Consequently, unauthenticated requests to subpaths like /api/route or /admin/observe/info bypass security checks. This can result in the disclosure of JVM, OS, and process metadata via the /observe/info endpoint. The issue is fixed in versions 4.14.6, 4.18.2, and 4.20.0.

Affected products

  • Apache Software Foundation Camel Platform HTTP Main 4.14.1 to 4.14.5, 4.18.0 to 4.18.1
  • Red Hat Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 4.18.1

Timeline

  • 2026-04-26: disclosed: Initial disclosure on oss-security mailing list
  • 2026-04-27: advisory: NVD and Apache advisory published
  • 2026-05-14: patched: Red Hat released security advisory RHSA-2026:17668

References

Related threats