CVE-2026-92142 | Apache Karaf up to 4.4.11 JMX MBean Server Guard createMBean/registerMBean/unregisterMBean access control

SecurityVulns

A vulnerability marked as critical has been reported in Apache Karaf up to 4.4.11. Affected by this issue is the function createMBean/registerMBean/unregisterMBean of the component JMX MBean Server Guard. This manipulation causes improper access controls.

This vulnerability is tracked as CVE-2026-92142. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More