Path traversal in Apache Camel - CVE-2026-66906

 

Path traversal in Apache Camel - CVE-2026-66906

Published: August 25, 2026


Vulnerability identifier: #VU145146
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-66906
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to create or overwrite files outside the intended download directory.

The vulnerability exists due to path traversal in the downloadBlobToFile operation when processing blob names from a consumed container. A remote attacker can place a blob with a crafted name containing parent-directory segments to create or overwrite files outside the intended download directory.

Exploitation requires the ability to influence blob names present in the consumed Azure Storage container.


Affected software

Apache Camel

How to mitigate CVE-2026-66906

Install security update from vendor's website.

Apache Camel - addressed in versions 4.14.9, 4.18.4, 4.22.0

External References

Related Security Bulletins