Executive brief
Apache Camel K is an integration platform that deploys integration services on Kubernetes. A vulnerability allows tenant-controlled Maven repository settings to inject and execute arbitrary code within the operator pod, potentially giving attackers the full privileges of the Kubernetes operator component.
Technical details
The vulnerability is an eval injection flaw in dynamically evaluated Maven configuration directives. The operator pod insufficiently neutralizes user-supplied or tenant-controlled repository content when processing Maven configuration, allowing arbitrary expressions to be evaluated at the Maven execution layer. An attacker with tenant access can craft malicious Maven repository metadata or configuration that executes arbitrary code within the operator pod context. This grants the attacker operator-level privileges in the Kubernetes cluster. The issue is resolved in versions 2.9.3, 2.10.2, and 2.11.0.
Affected products
- Apache Camel K 2.0.0 to 2.9.2, 2.10.0 to 2.10.1
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: Fixes released in versions 2.9.3, 2.10.2, 2.11.0