Input validation error in Apache Camel - CVE-2026-47323

 

Input validation error in Apache Camel - CVE-2026-47323

Published: August 25, 2026


Vulnerability identifier: #VU145285
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47323
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code or write arbitrary files.

The vulnerability exists due to improper input validation in the CXF and Knative HeaderFilterStrategy implementations when handling HTTP requests to CXF-RS or CXF-SOAP endpoints. A remote attacker can inject Camel-internal headers to execute arbitrary code or write arbitrary files.

Exploitation requires a route that forwards messages from affected endpoints to header-driven components such as camel-exec or camel-file.


Affected software

Apache Camel

How to mitigate CVE-2026-47323

Install security update from vendor's website.

Apache Camel - addressed in versions 4.14.6, 4.18.2, 4.19.0

External References

Related Security Bulletins