Deserialization of Untrusted Data in Apache Camel - CVE-2026-40858

 

Deserialization of Untrusted Data in Apache Camel - CVE-2026-40858

Published: August 25, 2026


Vulnerability identifier: #VU145340
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40858
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to unsafe deserialization in the ProtoStream-based remote aggregation repository of the camel-infinispan component when deserializing data read from a remote Infinispan cache during aggregation repository operations. A remote user can write a crafted serialized Java object to the cache to execute arbitrary code.

Exploitation requires the ability to write to the Infinispan cache used by the application.


Affected software

Apache Camel

How to mitigate CVE-2026-40858

Install security update from vendor's website.

Apache Camel - addressed in versions 4.14.7, 4.18.2, 4.20.0

External References

Related Security Bulletins