CVE-2026-91012

CVE-2026-91012 published: org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that the result stays i...

View full NVD advisory → ← Back to CVE watch