CVE-2026-91006 Apache Karaf 命令注入漏洞
影响攻击者可以 Karaf 进程用户身份执行任意操作系统命令
Apache Karaf 的实例管理服务 InstanceServiceImpl 在拼接启动子 JVM 的命令行时,未对调用方传入的 javaOpts 做引号或转义处理,随后通过 /bin/sh(Unix)或 cscript(Windows)执行。当 javaOpts 中包含 ;、|、`、$(...) 等 shell 元字符时,会被 shell 解释执行,从而造成任意命令执行。
影响范围
Apache Karaf 的 instance-management 服务(InstanceServiceImpl)受影响;具体受影响版本范围暂无公开信息,需以官方公告为准。
漏洞详情
漏洞类型为操作系统命令注入。成因是命令字符串拼接时未对 javaOpts 进行安全转义或加引号,导致用户可控内容被 shell 当作命令语法解析。利用方式是通过 instance:create、instance:start、instance:restart、instance:change-opts 等 shell 命令,或对应的 InstanceMBean JMX 操作(createInstance、startInstance、changeJavaOpts、cloneInstance)传入含 shell 元字符的 javaOpts。
利用条件与风险
利用前提是攻击者能够访问并调用上述 instance:* 命令或 InstancesMBean JMX 操作,且相关命令作用域未做严格角色限制(存在 fail-open 配置缺口)。一旦满足条件,即可在 Karaf 进程权限下执行任意命令,实战风险高。
修复建议
官方修复方案暂无公开信息,建议关注 Apache Karaf 官方安全公告并升级到修复版本。临时缓解:在 etc/system.properties 中设置 karaf.secured.command.compulsory.roles=admin 以关闭未配置命令作用域的 fail-open 缺口;通过 etc/users.properties 角色分配限制可访问 instance:* 命令和 InstancesMBean 的主体;将传入 instance:create/instance:start/instance:change-opts/InstancesMBean 的 javaOpts 视为不可信输入,仅允许完全可信的操作员使用。
Apache Karaf’s instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The caller-supplied javaOpts value is spliced into that string unquoted. A javaOpts value containing shell metacharacters (;, |, `, $(…)) is interpreted by the shell instead of being passed to the JVM as an option, giving arbitrary OS command execution as the Karaf process user.
Reachable via the shell commands instance:create, instance:start, instance:restart, instance:change-opts, and the equivalent InstanceMBean JMX operations (createInstance, startInstance, changeJavaOpts, cloneInstance).
Mitigation * Set karaf.secured.command.compulsory.roles=admin in etc/system.properties to close the fail-open gap for all unconfigured command scopes.
* Restrict which principals can reach instance:* commands and InstancesMBean via etc/users.properties role assignments.
* Treat javaOpts passed to instance:create/instance:start/instance:change-opts/InstancesMBean as untrusted input only from fully-trusted operators.