{"id":"CVE-2026-91006","title":"Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)","summary":"Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts…","severity":"none","cwe":["CWE-78"],"vendor":"Apache Software Foundation","product":"org.apache.karaf:org.apache.karaf.instance.core","affected":["org.apache.karaf:org.apache.karaf.instance.core < 4.4.12"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T10:44:32.652Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-91006","references":[{"url":"https://lists.apache.org/thread/olzy0yjw82b20w59vonfjr1x7v5yzocr"}],"tags":["cve.org"],"ingestedAt":"2026-09-28T11:08:06.673Z","slug":"CVE-2026-91006","body":"## Overview\n\nApache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.\n\n\nReachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).\n\nMitigation   *  Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.\n  *  Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.\n  *  Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.\n\n## Affected\n\n- `org.apache.karaf:org.apache.karaf.instance.core < 4.4.12`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}