
A PoC/exploit has been discovered for vulnerability CVE-2026-40858 PT ID: PT-2026-35386 Vendor: Apache Software Foundation Product: Apache Camel Description: The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using http://java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized Java object that, when read during normal aggregation repository operations such as get or recover, results in arbitrary code execution in the context of the application. This issue affects Apache Camel: from 4.0.0 before 4.14.7, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35386 • https://github.com/oscerd/CVE-2026-40858 #dbugs_vuln
Post summary
The text announces a discovered PoC for CVE‑2026‑40858, provides technical details of an RCE via deserialization, and links to code, but does not report active exploitation or a patch.



