Description
Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.


Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).

Mitigation  * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.
* Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.
* Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.
Published: 2026-09-28
Score: n/a
EPSS: n/a
KEV: No
Impact: Arbitrary OS command execution
Action: Apply Mitigation
AI Analysis

Impact

Apache Karaf's InstanceService implementation constructs a command line to launch child JVMs by concatenating user‑supplied javaOpts into a shell command. Because the value is not quoted, shell metacharacters such as ;, |, `, and $(…) are interpreted by /bin/sh or cscript, allowing an attacker who can invoke instance:create, instance:start, instance:restart, or the corresponding JMX operations to execute arbitrary commands with the credentials of the Karaf process. This is an OS command injection flaw, identified as CWE‑78, and provides full control over the host operating system.

Affected Systems

Both the service‑side and JMX interfaces of Apache Karaf expose this behavior. The vulnerability affects all deployments of Apache Karaf where the InstanceService is reachable, regardless of version, because no specific product version is listed. Administrators who grant users permission to run the instance:* commands or the InstanceMBean methods may inadvertently expose the injection vector.

Risk and Exploitability

Because the flaw relies on command‑line concatenation and unquoted input, exploiting it does not require complex prerequisites; an attacker with access to the Karaf command shell or JMX interface can inject shell metacharacters to run arbitrary commands. The CVSS score is not provided, but the lack of enforcement on the javaOpts parameter indicates a high‑risk vulnerability. EPSS is not available and KEV is not listed, yet the potential for remote command execution remains significant. Mitigations focus on restricting command access or treating the parameter as untrusted input.

Generated by OpenCVE AI on September 28, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail‑open gap for all unconfigured command scopes.
  • Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.
  • Treat javaOpts passed to instance:create, instance:start, instance:change-opts, or InstancesMBean as untrusted input only from fully‑trusted operators.

Generated by OpenCVE AI on September 28, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation  * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.
Title Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
Weaknesses CWE-78
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T10:44:32.652Z

Reserved: 2026-09-14T15:56:23.927Z

Link: CVE-2026-91006

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T11:16:48.200

Modified: 2026-09-28T11:16:48.200

Link: CVE-2026-91006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T12:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')