
A PoC/exploit has been discovered for vulnerability CVE-2026-40022 PT ID: PT-2026-35385 Vendor: Apache Software Foundation Product: Apache Camel Platform HTTP Main Description: When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or http://camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes derive the authentication path from properties.getPath() when camel.server.authenticationPath / http://camel.management.authenticationPath is not explicitly set. Combined with the Vert.x sub-router mounting model - the sub-router is mounted at path* and the authentication handler is registered inside the sub-router at the resolved path - this causes the authentication handler to match only the exact configured context path, not its subpaths. Unauthenticated requests to subpaths such as /api/route or /admin/observe/info therefore reach protected business routes and management endpoints without being challenged for credentials. The /observe/info endpoint can disclose runtime metadata such as the user, working directory, home directory, process ID, JVM and operating system information. This issue affects Apache Camel: from 4.14.1 before 4.14.6, from 4.18.0 before 4.18.2. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35385 • https://github.com/oscerd/CVE-2026-40022 #dbugs_vuln
Post summary
A Proof of Concept and exploit code for CVE-2026-40022 in Apache Camel has been released, detailing a path traversal authentication bypass that could expose runtime metadata, but no active exploitation is reported.



