CVE-2026-91085 | Apache Karaf up to 4.4.11 ACL Configuration org.apache.karaf.command.acl.config.cfg SecuredSessionFactoryImpl.checkSecurity privileges management
A vulnerability was found in Apache Karaf up to 4.4.11. It has been rated as critical. This affects the function SecuredSessionFactoryImpl.checkSecurity of the file etc/org.apache.karaf.command.acl.config.cfg of the component ACL Configuration. Performing a manipulation results in improper privilege management.
This vulnerability was named CVE-2026-91085. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More