CVE-2026-91085

CVE-2026-91085 published: Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command.acl.<scope>.cfg). SecuredSessionFactoryImpl.checkSecurity() resolves the roles required for an invocation and, when no ACL rule matches ...

View full NVD advisory → ← Back to CVE watch