Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.


Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).

Mitigation  * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.
* Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.
* Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache karaf
Vendors & Products Apache
Apache karaf

Mon, 28 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(...)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user. Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance). Mitigation  * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes. * Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments. * Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.
Title Apache Karaf: OS Command Injection in Child-Instance Launch (instance:* / InstancesMBean)
Weaknesses CWE-78
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-28T13:10:12.951Z

Reserved: 2026-09-14T15:56:23.927Z

Link: CVE-2026-91006

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T11:16:48.200

Modified: 2026-09-28T14:17:22.283

Link: CVE-2026-91006

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:00:15Z

Weaknesses