CVE-2026-80352
Apache Camel K has a critical code injection vulnerability that lets an authorized custom resource author inject arbitrary Kubernetes objects. This can allow an attacker to create resources with operator privileges. The issue is fixed in versions 2.9.3, 2.10.2, and 2.11.0.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Apache Camel K versions 2.0.0 through 2.9.2, and 2.10.1 through 2.10.1 (i.e., before 2.9.3 and before 2.10.2).
Real-world impact
An attacker who can author a custom resource can create arbitrary Kubernetes objects with the operator's privileges, potentially leading to full cluster compromise.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability can be exploited remotely with no authentication, allowing an attacker to modify the system with high confidentiality, integrity, and availability impact.
What to do about it
- 01Upgrade Apache Camel K to version 2.9.3, 2.10.2, or 2.11.0 or later.
NVD-referenced vendor advisory
Timeline
- Sep 10, 2026 · 4d agoPublishedDisclosed and added to the National Vulnerability Database.
- Sep 10, 2026 · 3d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.