-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --- title: "Apache Camel Security Advisory - CVE-2026-80354" date: 2026-09-08T11:00:00+02:00 url: /security/CVE-2026-80354.html draft: false type: security-advisory cve: CVE-2026-80354 severity: MODERATE summary: "Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace" description: "Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue." mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 2.9.3), which fixes the issue." credit: "This issue was discovered by internal analysis" affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.0 before 2.10.2" fixed: 2.9.3, 2.10.2 and 2.11.0 - --- The pull requests https://github.com/apache/camel-k/pull/6784 (2.11.x), https://github.com/apache/camel-k/commit/047e359168c473d88cd3f3f848904255451d284f (2.10.x) and https://github.com/apache/camel-k/commit/46b98e7a46575fcbe3e66192d842092047259886 (2.9.x) refer to the commits that resolved the issue, and have more details. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqf/ggACgkQrtxqiqrK h1Yl9g//X2wDb8D2MCAbMmP/Py9QMCLlF7zUUSc7+zgmh55GXUVAID3/weOAvZER OCt1fRCGcIMiDqC+kdTtB2XH4TzlhFv3V6zPUzURJ+BK2K9wuzHP3Sm9x6DHGF1u PJ63e1x4cH3Z0GqXeT2hGskqopzo89N19Utq7Vflnb05ll99wkOyOEh3Ca8Ih9Ex ApuwTc3nu0SVIUcfA5x6lbzSVLxAOuROPRNMNbbU178GV77cek9lR3fJY6tydFz7 NpvyeS3aYrd1YTsR/zYRYOfU2uMQkb4du2IdjSzK7JwD+JPddpkIWWewHszaTP7T 5lZ6Wv/tD6xGnaxKfvsEEfgrRYSmc9OQnzIw6KyCxr7Pd/LTOxK58SZHhFk8fBi5 +yRVlVAnKZ3CFTlpXC8CoSFXvTf4pa4/cD3VIEfYYsnQfc8Yr9DnbYTGvARiiqrY bITlWF7h9lSMR0cXCAgCzgU2tsdJiUt86AQXlLUYgs3qptCm02bBBftjTg3vEUHl pJVCWIz4FRypv7SAWrLgLjHlAHOtZv7vWYQ8vKM7QhaTpe1ZIokvsHrGfKccsU0S wZxtMYkeWfeI1fNKz/cLnpITwC/7tqlgkrjft+vsLqqFKc358CXS9c3ue0ueYd7Z 6QhdSr2WF2rCcwB3fKIuezzo4pxO01QBzXOHommk1jDPI0hECj0= =hi70 -----END PGP SIGNATURE-----