CVE-2026-45760: Apache Software Foundation Apache Camel K
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace. This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue.
Affected products
- Apache Software Foundation Apache Camel K: from 2.0.0, before 2.8.1 (fixed in 2.8.1); from 2.9.0, before 2.9.2 (fixed in 2.9.2); from 2.10.0, before 2.10.1 (fixed in 2.10.1)
Published 2026-05-21. Last modified 2026-07-23.