CVE-2026-91048

CVE-2026-91048 published: The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer...

View full NVD advisory → ← Back to CVE watch