-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --- title: "Apache Camel Security Advisory - CVE-2026-80351" date: 2026-09-08T11:00:00+02:00 url: /security/CVE-2026-80351.html draft: false type: security-advisory cve: CVE-2026-80351 severity: CRITICAL summary: "Camel K Tenant repositories reach Maven execution inside operator pod" description: "Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue." mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 2.9.3), which fixes the issue." credit: "This issue was discovered by internal analysis" affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.0 before 2.10.2" fixed: 2.9.3, 2.10.2 and 2.11.0 - --- The pull requests https://github.com/apache/camel-k/pull/6786 (2.11.x), https://github.com/apache/camel-k/commit/42b4573a779c4202a205a088e42c781cea3e4ed4 (2.10.x) and https://github.com/apache/camel-k/commit/954ff98054a28e3369712ecc8522811a70afa802 (2.9.x) refer to the commits that resolved the issue, and have more details. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf0akACgkQrtxqiqrK h1akiw//ZckJzq8iyF7fEGbSZYVrZX1OtW4WpG205LyIEmAa8tfXCAeI3a380+fL 5zIGHXhia20rNB3MMW7Ut4Zg1LQgebPG/jdwkYtWQwzktOogJmsDZWB7CYcowi/i EFMCV8H09VqIXFxGcB93F+qEQTAiLVLG3p9TToMpK6B6+YKS9d2Uc2t+7Glfxd1c 9ciSaGsv+vbiqLECbCH6fpcCTDbA0pH+KsBwhySJoT2weZ1t+Huta3n6NXHlZDfS cy+2om5awRByRl1qnc+4kk9WyBpvVr8hJBuRzpm+q2woCzWoiX72ns/674MCzPHg cPRzAsZeMXrDKISCev+L83F+8EaciEF6KBj8/limXz7nKqULrfQ1PQT0HPBdysJn 4ee3iYemRrd2abfzovqARO1YGFjKe/4nwepaezvtlL6eDEj4O9mkW7YjktEbo0IR 6tEjhkVkrhrmJCF9t1mqhkIbZD2A3PACrogVBeekmk0uY8+9iEiW4fVFjvDb2rkT 7eKg7E1ypmNRPvC2GGou1R4GPQpISTZ/6W1MOh2IXaKvQ5VaosewJIJAc/deJa5J 0WyL1DLSHbSootpY2n12WiVcR2gZGw8S+fhDHJYBzT7H3Li351zEH0a65egwAFWX doYEfmuQTWbLJPiQDcu4rs00h2wWrvyKOpL6Iiu6CEFr6+E923Q= =sGkD -----END PGP SIGNATURE-----