SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-80352

CRITICAL · CVSS 9.8 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A YAML injection vulnerability in Apache Camel K allows authorized users to inject arbitrary Kubernetes objects into custom resource configurations, potentially leading to unauthorized resource creation with the operator's privileges. This issue affects versions 2.0.0 through 2.9.2 and 2.10.1, making it critical for organizations using these versions to upgrade to 2.9.3, 2.10.2, or 2.11.0 to mitigate the risk. Kubernetes administrators and security teams should prioritize this vulnerability to protect their environments from potential exploitation.

CVE
CVE-2026-80352
Severity
CRITICAL
CVSS
9.8
EPSS
0.33%
Apache Kubernetes

Original NVD Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource creation with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.