Input validation error in Apache Camel - CVE-2026-46592
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect the invoked SOAP operation.
The vulnerability exists due to improper input validation in the Camel CXF SOAP producer when bridging an inbound HTTP request into a cxf: producer. A remote attacker can send a crafted HTTP request with operation-selection headers to redirect the invoked SOAP operation.
No credentials are required when the bridging HTTP consumer is unauthenticated.