Junglewise Threat Intelligence

CVE-2026-48204: Apache Camel access control bypass in MongoDB GridFS component

CVE-2026-48204 · Severity: critical · CVSS 9.8 · Published 2026-07-06

Vendors: Apache Software Foundation, Apache.

Executive brief

Apache Camel is an integration framework used to connect different software systems. A vulnerability in its MongoDB GridFS component allows unauthorized users to manipulate database operations via web requests. An attacker could exploit this to delete files, view sensitive data, or list all files in a database without needing any login credentials.

Technical details

The camel-mongodb-gridfs producer incorrectly processes control headers that do not follow the standard 'Camel' prefix naming convention. Specifically, headers like 'gridfs.operation' and 'gridfs.metadata' are not filtered by the HttpHeaderFilterStrategy when bridging an HTTP consumer to a MongoDB producer. This allows a remote, unauthenticated attacker to override the intended database operation (e.g., changing an upload to a delete) and inject NoSQL operators through the metadata header. The vulnerability is rooted in improper input validation and access control within the header processing logic. Patches are available in versions 4.14.8, 4.18.3, and 4.21.0, which rename the control headers to use the 'CamelGridFs' prefix.

Affected products

  • Apache Camel Mongodb Gridfs 4.0.0 to 4.14.7, 4.15.0 to 4.18.2, 4.19.0 to 4.20.0

Timeline

  • 2026-07-05: disclosed: Initial disclosure on oss-security list
  • 2026-07-06: advisory: GitHub Advisory and NVD publication
  • 2026-07-24: other: Advisory reviewed and updated

References