SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-80354

HIGH · CVSS 8.1 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

An authorization bypass vulnerability in Apache Camel K allows tenants to access secrets from the operator namespace by referencing them by name, potentially compromising the confidentiality of secrets belonging to other tenants or operator components. Organizations using affected versions (2.0.0 to 2.9.2 and 2.10.1) should prioritize upgrading to versions 2.9.3, 2.10.2, or 2.11.0 to mitigate this risk. This issue is particularly critical for multi-tenant environments where sensitive data isolation is essential.

CVE
CVE-2026-80354
Severity
HIGH
CVSS
8.1
EPSS
0.22%
Apache

Original NVD Description

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)