CVE-2026-40858General(apache / camel)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized Java object that, when read during normal aggregation repository operations such as get or recover, results in arbitrary code execution in the context of the application. This issue affects Apache Camel: from 4.0.0 before 4.14.7, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.7. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2. The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-23322 refers to the various commits that resolved the issue, and have more details. This issue follows the same class of vulnerability previously addressed in CVE-2024-22369, CVE-2024-23114 and CVE-2026-25747.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-26); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
camel

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-26: 1Mentions · 2026-04-27: 1Mentions · 2026-07-10: 1Mentions · 2026-08-15: 1PoC Mentioned / Linked · 2026-07-10: 1Exploit Tool / Code · 2026-07-10: 1Patch / Workaround · 2026-08-15: 1Technical Details · 2026-04-27: 1Technical Details · 2026-07-10: 1Technical Details · 2026-08-15: 104-2604-2707-1008-15
Signal classification3 categories
General
250.0%
PoC
125.0%
Patch
125.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-271
General1
2026-07-101
PoC1
2026-08-151
Patch1
Full discourse4 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-40858 PT ID: PT-2026-35386 Vendor: Apache Software Foundation Product: Apache Camel Description: The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using http://java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized Java object that, when read during normal aggregation repository operations such as get or recover, results in arbitrary code execution in the context of the application. This issue affects Apache Camel: from 4.0.0 before 4.14.7, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35386 • https://github.com/oscerd/CVE-2026-40858 #dbugs_vuln

    Post summary

    The text announces a discovered PoC for CVE‑2026‑40858, provides technical details of an RCE via deserialization, and links to code, but does not report active exploitation or a patch.

    010522.3K
    3.4K followersView on X
  • Innora.ai@Innora_sg
    Patch

    CVE-2026-40858 (CVSS 8.8): Apache Camel's camel-infinispan deserializes Infinispan cache data with raw ObjectInputStream — no ObjectInputFilter. Write to the cache → in-app RCE. Fixed in 4.14.7 / 4.18.2 / 4.20.0. Found by Feng Ning, http://Innora.ai #CVE #Java #AppSec #InfoSec

    Post summary

    The post details an RCE in Apache Camel’s infinispan component, confirms the CVSS rating, and identifies the fixed versions, highlighting a patch availability.

    01020104
    22 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40858 The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using http://java.io.ObjectInputStream… https://www.cve.org/CVERecord?id=CVE-2026-40858

    Post summary

    The text notes CVE-2026-40858 as a deserialization flaw in the camel-infinispan component, but offers no further details on exploitation, patching, or PoC.

    00000105
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40858 CVE-2026-40858 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40858

    Post summary

    A terse notice for CVE‑2026‑40858 that directs readers to Vulmon for more information, without further detail on exploitation, patches, or technical aspects.

    0000042
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---
Appapachecamel4.19.0--

Explore more