Junglewise Threat Intelligence

CVE-2026-91006: Apache Karaf instance-management command injection in javaOpts

CVE-2026-91006 · Severity: info · Published 2026-09-28

Vendors: Apache.

Executive brief

Apache Karaf's instance-management service allows administrators to create and configure child JVM instances through shell commands or JMX operations. When building the command line to launch these instances, the service concatenates user-supplied Java options directly into a shell command without proper escaping. An attacker with access to these commands could inject shell metacharacters to execute arbitrary operating system commands with the privileges of the Karaf process.

Technical details

The InstanceServiceImpl builds shell commands via string concatenation of caller-supplied javaOpts without quoting or escaping, then executes the result through /bin/sh (Unix) or cscript (Windows). Shell metacharacters (;, |, `, $(...)) in javaOpts are interpreted by the shell rather than passed to the JVM, enabling arbitrary command execution. The vulnerability is reachable via instance:create, instance:start, instance:restart, instance:change-opts shell commands and equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).

Affected products

  • Apache Karaf

Timeline

  • 2026-09-28: disclosed

References

Related threats