Executive brief
Apache Karaf's instance-management service allows administrators to create and configure child JVM instances through shell commands or JMX operations. When building the command line to launch these instances, the service concatenates user-supplied Java options directly into a shell command without proper escaping. An attacker with access to these commands could inject shell metacharacters to execute arbitrary operating system commands with the privileges of the Karaf process.
Technical details
The InstanceServiceImpl builds shell commands via string concatenation of caller-supplied javaOpts without quoting or escaping, then executes the result through /bin/sh (Unix) or cscript (Windows). Shell metacharacters (;, |, `, $(...)) in javaOpts are interpreted by the shell rather than passed to the JVM, enabling arbitrary command execution. The vulnerability is reachable via instance:create, instance:start, instance:restart, instance:change-opts shell commands and equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).
Affected products
- Apache Karaf
Timeline
- 2026-09-28: disclosed