CVE-2026-40022PoC(apache / camel)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes derive the authentication path from properties.getPath() when camel.server.authenticationPath / camel.management.authenticationPath is not explicitly set. Combined with the Vert.x sub-router mounting model - the sub-router is mounted at _path_* and the authentication handler is registered inside the sub-router at the resolved path - this causes the authentication handler to match only the exact configured context path, not its subpaths. Unauthenticated requests to subpaths such as /api/_route_ or /admin/observe/info therefore reach protected business routes and management endpoints without being challenged for credentials. The /observe/info endpoint can disclose runtime metadata such as the user, working directory, home directory, process ID, JVM and operating system information. This issue affects Apache Camel: from 4.14.1 before 4.14.6, from 4.18.0 before 4.18.2. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, they are suggested to upgrade to 4.14.6. If users are on the 4.18.x LTS releases stream, they are suggested to upgrade to 4.18.2.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288CWE-551

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-24)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-07-07: 1Mentions · 2026-07-24: 2PoC Mentioned / Linked · 2026-07-07: 1PoC Mentioned / Linked · 2026-07-24: 2Exploit Tool / Code · 2026-07-07: 1Technical Details · 2026-07-07: 104-2604-2707-0707-24
Signal classification2 categories
PoC
360.0%
General
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-271
General1
2026-07-071
PoC1
2026-07-242
PoC2
Full discourse5 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-40022 PT ID: PT-2026-35385 Vendor: Apache Software Foundation Product: Apache Camel Platform HTTP Main Description: When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or http://camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes derive the authentication path from properties.getPath() when camel.server.authenticationPath / http://camel.management.authenticationPath is not explicitly set. Combined with the Vert.x sub-router mounting model - the sub-router is mounted at path* and the authentication handler is registered inside the sub-router at the resolved path - this causes the authentication handler to match only the exact configured context path, not its subpaths. Unauthenticated requests to subpaths such as /api/route or /admin/observe/info therefore reach protected business routes and management endpoints without being challenged for credentials. The /observe/info endpoint can disclose runtime metadata such as the user, working directory, home directory, process ID, JVM and operating system information. This issue affects Apache Camel: from 4.14.1 before 4.14.6, from 4.18.0 before 4.18.2. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35385 • https://github.com/oscerd/CVE-2026-40022 #dbugs_vuln

    Post summary

    A Proof of Concept and exploit code for CVE-2026-40022 in Apache Camel has been released, detailing a path traversal authentication bypass that could expose runtime metadata, but no active exploitation is reported.

    0001301.6K
    3.4K followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-40022: A PoC/exploit has been discovered for vulnerability CVE-2026-40022 PT ID: PT-2026-35385 Vendor: Apache Software Foundation Product: Apache Camel Platform HTTP Main Description: When authentication is enabled on the Apache Camel embedded HTTP server or…

    Post summary

    A PoC/exploit has been identified for CVE-2026-40022 in Apache Camel, but the post lacks detailed code, active exploitation evidence, or patch information.

    1000080
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    Source: X search for PoC exploit 2026 Posted: 2026-07-07T11:25:40.000Z Likes: 12 0day Intel: A PoC/exploit has been discovered for vulnerability CVE-2026-40022

    Post summary

    A proof‑of‑concept or exploit for CVE‑2026‑40022 has been discovered, but the post lacks details such as actual code, patch information, or evidence of live attacks.

    1000071
    326 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40022 When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /… https://www.cve.org/CVERecord?id=CVE-2026-40022

    Post summary

    The snippet merely references CVE-2026-40022 and links to its CVE record, but offers no proof‑of‑concept, exploit details, active usage evidence, or patch information.

    00000121
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40022 CVE-2026-40022 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40022

    Post summary

    The post merely cites the CVE ID twice and provides a generic link to a vulnerability details page, offering no further context or technical information.

    0000048
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more