{"id":"CVE-2026-91006","published":"2026-09-28T11:16:48.200","lastModified":"2026-09-29T22:19:03.517","description":"Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.\n\n\nReachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).\n\nMitigation   *  Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.\n  *  Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.\n  *  Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/olzy0yjw82b20w59vonfjr1x7v5yzocr","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/28/3","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows for arbitrary OS command execution due to unquoted string concatenation in the javaOpts parameter, enabling attackers to inject shell commands.","exploitability":"Exploitation requires access to the instance management commands or MBean operations, making it moderately difficult. Precondition is the presence of untrusted input in javaOpts.","blast_radius":"If exploited, the impact could be severe, as it allows for arbitrary command execution as the Karaf process user, potentially leading to full system compromise.","remediation":"Restrict access to instance management commands and MBean operations in etc/users.properties and enforce the use of trusted operators only.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","command-injection","jmx","instance-management"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:06:42.810Z"}}