CVE-2026-91085 | Apache Karaf up to 4.4.11 ACL Configuration org.apache.karaf.command.acl.config.cfg SecuredSessionFactoryImpl.checkSecurity privileges management

SecurityVulns

A vulnerability was found in Apache Karaf up to 4.4.11. It has been rated as critical. This affects the function SecuredSessionFactoryImpl.checkSecurity of the file etc/org.apache.karaf.command.acl.config.cfg of the component ACL Configuration. Performing a manipulation results in improper privilege management.

This vulnerability was named CVE-2026-91085. The attack may be initiated remotely. There is no available exploit.

Upgrading the affected component is advised.VulDB Recent EntriesRead More