-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --- title: "Apache Camel Security Advisory - CVE-2026-80352" date: 2026-09-08T11:00:00+02:00 url: /security/CVE-2026-80352.html draft: false type: security-advisory cve: CVE-2026-80352 severity: CRITICAL summary: "Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects" description: "Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue." mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 2.9.3), which fixes the issue." credit: "This issue was discovered by internal analysis" affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.0 before 2.10.2" fixed: 2.9.3, 2.10.2 and 2.11.0 - --- The pull requests https://github.com/apache/camel-k/pull/6785 (2.11.x), https://github.com/apache/camel-k/commit/021f4baa7678e6244077ae7fb0edb41a3543757c (2.10.x) and https://github.com/apache/camel-k/commit/f0659822418eb3c0ab2b2090a797d7f0b8275763 (2.9.x) refer to the commits that resolved the issue, and have more details. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf/L4ACgkQrtxqiqrK h1ZyGA/8Df6FWCClQdoNuMD97qRYP0LFG6vIttAi7q4NboZ1Gy8PBo+d+q9HPern TJ3xSt6OGJ2CZy0MkmqAUtFis+wuRO6eiNJx7be+9MMUVgfZiBnFebgWCPgf/dvi OAM/TPXyXOhYjwaa5H2U0pKxWSk/c+gVwDpTzj1SAUfuiwEr+WBvXiYZlA2FLb+I FIp6IbygA3eb3mgrFrs8cJRnFCJpE1p1gZmK5jxXZ/jFlNkxXNjDcQuBtYy6zZHr 1qEVC3M4DMtrJeEJdIF/tzX+R+ObRufdNRWKrrM9Utj+leJYe9dg1kApQub+m3vc ivkqWjMZ+DZw2Set795a43Fy/Zos6ixM+lyJ3fnkhZMTL25kLkqg+28zjakCBRcR O4bwzcW2msYYNLJtP+pjg1CEJI8obnFB7gy24xYVAkphNGZOy7z1MIajwUbpZ+QZ MEWNlZ0ZTFczMWaijGCda0MkEP8GD0iWjbMZlwRwJwksHecD2EuA1og7iRdCqHSf 0UVtD+hNgg7j4RjIlGi/C1niOHaforzLDeyLdaJHpvDTMb9LoEKgBsL7j3pI9ezP +tWDQ6PHos1G8KrYj4EJ/NAR5PnzFvzZdgRzl89X9YSKZFi0cB9OuF1C5N2L7gDb fe2DwhuqS0+64rbZjiUxbWcsj+DNvVkypRofwBZWPI0Vobx/WRY= =LAkH -----END PGP SIGNATURE-----