-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --- title: "Apache Camel Security Advisory - CVE-2026-80354" date: 2026-09-08T11:00:00+02:00 url: /security/CVE-2026-80354.html draft: false type: security-advisory cve: CVE-2026-80354 severity: MEDIUM summary: "Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace" description: "Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposing secrets belonging to other tenants or operator components. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue." mitigation: "Users are recommended to upgrade to version 2.11.0 (or 2.10.2 or 2.9.3), which fixes the issue." credit: "This issue was discovered by internal analysis" affected: "This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.0 before 2.10.2" fixed: 2.9.3, 2.10.2 and 2.11.0 - --- The pull requests https://github.com/apache/camel-k/pull/6784 (2.11.x), https://github.com/apache/camel-k/commit/047e359168c473d88cd3f3f848904255451d284f (2.10.x) and https://github.com/apache/camel-k/commit/46b98e7a46575fcbe3e66192d842092047259886 (2.9.x) refer to the commits that resolved the issue, and have more details. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDV4jKJJJXejlQHXMrtxqiqrKh1YFAmqpEnUACgkQrtxqiqrK h1brExAAs60dM5FU73Xjsa1yvfKM4LkqQl6TDwRthR9wIrYVE2leMyIs1vG9TjOT yfjRH4ZB5bkv5W2pWrJVP1nFsIMyGwRSVBWlo2u4Mv76rTRHKknd0Nhg1jMbpO/d eA/TOk085fUV8PvLVgzfTDKSROnwnW//fdwv2+OfdNQzoqq9cBrowvZLZ5OIqcv/ TURdT38KfJl/2hfLpV2wrEJr7oc3+zkbzkix1grac7JvNCvIoz2R3dDStQ0CB0Go 2KLLRZ72+DI6mCSbVaGIeL+ZLvTTuvNHdKqUeIEFshWSzs4+sHAzBVX+789WXRna rn8OCdEDPa5i08Uk/xhDfMZ0EfIPEdZHuXoLX/CAFETAG3ZxLHxpW2R+boiueGEz NmAnMQYiufMRrxNEX1BZ2UXkS0uG72mx613wbeyDt2sy4Cenn86JJpYKH1k+8dU2 LCjwtsZIse3UnBn8KvvFixBjkRUv9aeRPgTXwiVYN6GcwOpwE6R3H6qwmHK6AHtX iXIIqskxh1DkA4JvtvvDqS25ZIyuqh84Ewt32wA4jwOUv1opXbW5kGK58AWH+Le2 j1KVmIxBi8opaGGJl7GT2dPxMpVvwiGMk+k6ocwXHzgJXdLQ1aRgJEemFBtIIqvj bJSyORDn+vKYOMbWRSzGxa2ySMVekk+BTGUd+1/oNo+0Q5y+kRw= =HnJJ -----END PGP SIGNATURE-----