CVE-2026-91006 | Apache Karaf up to 4.4.11 Instance Management InstanceServiceImpl javaOpts os command injection

SecurityVulns

A vulnerability was found in Apache Karaf up to 4.4.11. It has been declared as critical. This vulnerability affects the function InstanceServiceImpl of the component Instance Management. The manipulation of the argument javaOpts results in os command injection.

This vulnerability was named CVE-2026-91006. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More