CVE-2026-33453Disclosure(apache / camel)

MEDIUMCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec) The camel-coap component maps incoming CoAP request URI query parameters directly into Camel Exchange In message headers without applying any HeaderFilterStrategy.   Specifically, CamelCoapResource.handleRequest() iterates over OptionSet.getUriQuery() and calls camelExchange.getIn().setHeader(...) for every query parameter. CoAPEndpoint extends DefaultEndpoint rather than DefaultHeaderFilterStrategyEndpoint, and CoAPComponent does not implement HeaderFilterStrategyComponent; the component contains no references to HeaderFilterStrategy at all. As a result, an unauthenticated attacker who can send a single CoAP UDP packet to a Camel route consuming from coap:// can inject arbitrary Camel internal headers (those prefixed with Camel*) into the Exchange. When the route delivers the message to a header-sensitive producer such as camel-exec, camel-sql, camel-bean, camel-file, or template components (camel-freemarker, camel-velocity), the injected headers can alter the producer's behavior. In the case of camel-exec, the CamelExecCommandExecutable and CamelExecCommandArgs headers override the executable and arguments configured on the endpoint, resulting in arbitrary OS command execution under the privileges of the Camel process. The producer's output is written back to the Exchange body and returned in the CoAP response payload by CamelCoapResource, giving the attacker an interactive RCE channel without any need for out-of-band exfiltration.                                                                                                                                                                         Exploitation prerequisites are minimal: a single unauthenticated UDP datagram to the CoAP port (default 5683). CoAP (RFC 7252) has no built-in authentication, and DTLS is optional and disabled by default. Because the protocol is UDP-based, HTTP-layer WAF/IDS controls do not apply. This issue affects Apache Camel: from 4.14.0 through 4.14.5, from 4.18.0 before 4.18.1, 4.19.0. Users are recommended to upgrade to version 4.18.1 or 4.19.0, fixing the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-915

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-04); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
camel

2 versions affected across 1 product

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Mentions · 2026-05-03: 1Mentions · 2026-05-04: 2Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-06: 1Exploit Tool / Code · 2026-07-06: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-03: 1Technical Details · 2026-07-06: 104-2604-2704-2805-0305-0407-06
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Exploit
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-271
Disclosure1
2026-04-281
Disclosure1
2026-05-031
Disclosure1
2026-05-042
Disclosure1General1
2026-07-061
Exploit1
Full discourse7 posts
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-33453 PT ID: PT-2026-35394 Vendor: Apache Software Foundation Product: Apache Camel Description: Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec) The camel-coap component maps incoming CoAP request URI query parameters directly into Camel Exchange In message headers without applying any HeaderFilterStrategy.   Specifically, CamelCoapResource.handleRequest() iterates over OptionSet.getUriQuery() and calls camelExchange.getIn().setHeader(...) for every query parameter. CoAPEndpoint extends DefaultEndpoint rather than DefaultHeaderFilterStrategyEndpoint, and CoAPComponent does not implement HeaderFilterStrategyComponent; the component contains no references to HeaderFilterStrategy at all. As a result, an unauthenticated attacker who can send a single CoAP UDP packet to a Camel route consuming from coap:// can inject arbitrary Camel internal headers (those prefixed with Camel*) into the Exchange. When the route delivers the message to a header-sensitive producer such as camel-exec, camel-sql, camel-bean, camel-file, or template components (camel-freemarker, camel-velocity), the injected headers can alter the producer's behavior. In the case of camel-exec, the CamelExecCommandExecutable and CamelExecCommandArgs headers override the executable and arguments configured on the endpoint, resulting in arbitrary OS command execution under the privileges of the Camel process. The producer's output is written back to the Exchange body and returned in the CoAP response payload by CamelCoapResource, giving the attacker an interactive RCE channel without any need for out-of-band exfiltration.                                                                                                                                                                         Exploitation prerequisites are minimal: a single unauthenticated UDP datagram to the CoAP port (default 5683). CoAP (RFC 7252) has no built-in authentication, and DTLS is optional and disabled by default. Because the protocol is UDP-based, HTTP-layer WAF/IDS controls do not apply. This issue affects Apache Camel: from 4.14.0 through 4.14.5, from 4.18.0 before 4.18.1, 4.19.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35394 • https://github.com/oscerd/CVE-2026-33453 #dbugs_vuln

    Post summary

    A PoC/exploit for CVE-2026-33453 in Apache Camel’s camel‑coap component has been released, enabling unauthenticated users to inject headers and achieve remote code execution via header‑sensitive producers.

    030762.2K
    3.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Multiple RCE vulnerabilities in Apache Camel components (CVE-2026-33453 / CVE-2026-33454 / CVE-2026-40453) CVE-2026-33453 - camel-coap allows header injection via URI query params, enabling unauthenticated RCE when routed to header-sensitive components (e.g. camel-exec). 👉 Affected: >= 4.14.0, <= 4.14.5 | >= 4.18.0, < 4.18.1 | 4.19.0 | Upgrade: 4.18.1 / 4.19.0 CVE-2026-33454 - camel-mail missing inbound header filtering allows attacker-controlled email headers to manipulate routes and trigger RCE in downstream components. 👉 Affected: >= 3.0.0, < 4.14.6 | >= 4.15.0, < 4.18.1 | Upgrade: 4.14.6 / 4.18.1 / 4.19.0 CVE-2026-40453 - Multiple components lack case-insensitive header filtering, enabling injection of Camel internal headers and leading to RCE/file write via downstream processors. 👉 Affected: >= 3.0.0, < 4.14.6 | >= 4.15.0, < 4.18.2 | >= 4.19.0, < 4.20.0 | Upgrade: 4.14.6 / 4.18.2 / 4.20.0

    Post summary

    An announcement of new critical RCE vulnerabilities in Apache Camel components, detailing affected versions and providing upgrade recommendations.

    00040107
    237 followersView on X
  • Technology Interpreters, Inc.@TechTranslators
    Disclosure

    Yesterday — CVE-2026-33453, camel-coap, CVSS 10. One UDP packet to port 5683 injects Camel headers. If your route hands them off to camel-exec, sql, bean, or file, that header rewrite turns into OS command execution. https://nvd.nist.gov/vuln/detail/CVE-2026-33453

    Post summary

    A newly disclosed vulnerability in camel-coap (CVE-2026-33453) with CVSS score 10 allows OS command execution via a single crafted UDP packet.

    1000134
    34 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-33453: Apache Camel CoAP Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04fgZFr0

    Post summary

    A general article headline with a link, but without explicit technical details, exploit code, or patch information, suggesting a broader overview rather than actionable content.

    0000042
    29 followersView on X
  • ケイ | 副業Webライター🇫🇷⚓⚽@Teeeda_worker
    Disclosure

    CVE-2026-33453の概要と影響、対策を簡潔に整理。 【脆弱性情報】 CVE-2026-33453 ApacheのApache Camelの脆弱性について https://www.cybernote.click/2026/04/28/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-33453-apache%e3%81%aeapache-camel%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/?utm_source=rss&utm_medium=rss&utm_campaign=%25e3%2580%2590%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e6%2583%2585%25e5%25a0%25b1%25e3%2580%2591-cve-2026-33453-apache%25e3%2581%25aeapache-camel%25e3%2581%25ae%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25ab%25e3%2581%25a4%25e3%2581%2584%25e3%2581%25a6 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The post is a concise overview of CVE-2026-33453, summarizing its impact and pointing to an external blog for detailed information, with no evidence of PoC, exploit, active attacks, or mitigation details.

    0000056
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33453 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap componen… https://www.cve.org/CVERecord?id=CVE-2026-33453

    Post summary

    CVE-2026-33453 has been announced as a vulnerability in Apache Camel’s camel-coap component, where object attributes can be improperly modified based on dynamic input.

    00000113
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33453 CVE-2026-33453 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33453

    Post summary

    The text simply repeats the CVE identifier and provides a link, but gives no additional context or details.

    0000056
    4.0K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---
Appapachecamel4.18.0--
Appapachecamel4.19.0--

Explore more