CVE-2026-80351

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
References
Link Resource
https://camel.apache.org/security/CVE-2026-80351.html Patch Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/09/10/14 Mailing List Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:camel:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-09-10 08:16

Updated : 2026-09-14 19:56


NVD link : CVE-2026-80351

Mitre link : CVE-2026-80351

CVE.ORG link : CVE-2026-80351


JSON object : View

Products Affected

apache

  • camel
CWE
CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')