ZeroHour
Product

Apache Camel K

3 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace

Apache Camel K CVE-2026-80354 lets tenants reference secrets by name in the operator namespace, exposing other tenants' secrets.

Apache disclosed a moderate authorization bypass (CVE-2026-80354) in Apache Camel K's Builder trait, where mavenProfiles ValueSources resolve tenant-named secrets in the operator namespace. A tenant can reference secrets by name, potentially exposing secrets belonging to other tenants or the operator. Affected versions are 2.0.0 before 2.9.3 and 2.10.1 before 2.10.2; fixes are available in 2.9.3 and 2.10.2.

CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects

Apache Camel K CVE-2026-80352 lets CR authors inject arbitrary Kubernetes objects via Master trait serviceAccountName YAML injection.

Apache disclosed a critical YAML injection vulnerability (CVE-2026-80352, improper control of code generation) in Apache Camel K's Master trait serviceAccountName setting. An authorized custom resource author can inject arbitrary Kubernetes objects, potentially enabling unauthorized resource manipulation. Affected versions are 2.0.0 before 2.9.3 and 2.10.1 before 2.10.2; fixes are available in 2.9.3 and 2.10.2.

CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod

Apache Camel K CVE-2026-80351 lets tenant-controlled Maven repository content execute code inside the operator pod; fixed in 2.9.3/2.10.2.

Apache disclosed a critical eval injection vulnerability (CVE-2026-80351) in Apache Camel K, where improperly neutralized directives in dynamically evaluated Maven configuration let tenant-controlled repository content reach Maven execution inside the operator pod. This can allow tenant-controlled content to influence code execution in the operator context. Affected versions are 2.0.0 before 2.9.3 and 2.10.1 before 2.10.2; fixes are available in 2.9.3 and 2.10.2.

Related CVEs

  • YAML injection in Apache Camel K lets CR authors create objects with operator privileges
    Apache Camel K contains a YAML injection flaw (CWE-94, improper control of code generation) in its handling of custom resource (CR) configuration, specifically exposed via the Master trait's serviceAccountName field. An authenticated user who is authorized to author Camel K custom resources can embed crafted YAML that causes the operator to apply arbitrary Kubernetes objects. Because the injected objects are created with the privileges of the Camel K operator's service account, an attacker can gain unauthorized creation of cluster resources, potentially enabling privilege escalation or lateral movement within the cluster. Users running Apache Camel K 2.0.0 through 2.9.2 or 2.10.1 are affected; fixed releases are 2.9.3, 2.10.2, and 2.11.0. No public proof-of-concept or in-the-wild exploitation is known, and no CVSS score has been assigned yet.
    · Apache Camel K >= 2.0.0 and < 2.9.3 (fixed in 2.9.3; also fixed in 2.11.0) · Apache Camel K >= 2.10.1 and < 2.10.2 (fixed in 2.10.2; also fixed in 2.11.0)niche
  • Eval injection in Apache Camel K lets tenants run code with operator privileges
    Apache Camel K contains an eval injection flaw (CWE-95) in its handling of dynamically evaluated Maven configuration. When tenant-controlled Maven repository content is processed, it is evaluated inside the Camel K operator pod without proper neutralization of directives, allowing repository content to steer code execution. A tenant can potentially execute arbitrary code with the privileges of the operator, which in multi-tenant clusters may enable cross-tenant compromise because the operator typically manages integrations across namespaces. Users running Apache Camel K from 2.0.0 before 2.9.3, and from 2.10.1 before 2.10.2, are affected, especially multi-tenant deployments where tenants can influence Maven repository settings. No public proof-of-concept or in-the-wild exploitation is known, the issue is not in CISA KEV, and a CVSS score has not yet been assigned.
    · Apache Camel K from 2.0.0 before 2.9.3 · Apache Camel K from 2.10.1 before 2.10.2niche
  • Cross-Tenant Secret Exposure via Authorization Bypass in Apache Camel K
    Apache Camel K, the Kubernetes-native integration runtime for Apache Camel, has an authorization flaw (CWE-639, user-controlled key) in its custom resource resolution: tenant-supplied values, such as the Builder trait's mavenProfiles ValueSources, cause the operator to resolve secrets by name from the operator's namespace instead of the tenant's own namespace. A tenant that can set a secret name on an Integration build resource can therefore have the operator pull in a secret belonging to another tenant or to operator components. An attacker with tenant-level access gains access to those secrets, potentially obtaining credentials shared across the multi-tenant cluster. Users running Apache Camel K 2.0.0 through 2.9.2 or version 2.10.1 are affected; fixes are available in 2.9.3, 2.10.2, and 2.11.0. No public proof of concept exists, the issue is not in CISA KEV, and no in-the-wild exploitation is known.
    · Apache Camel K >= 2.0.0 and < 2.9.3 (fixed in 2.9.3) · Apache Camel K 2.10.1 (fixed in 2.10.2); 2.11.0 is unaffectedniche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.