CVE-2026-40860General(apache / camel)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever the mapJmsMessage option is enabled (the default) and Camel acts as a JMS consumer, an attacker able to publish a crafted ObjectMessage to a queue or topic consumed by a Camel application could achieve remote code execution when a deserialization gadget chain was present on the classpath. The same handling was reached transitively through camel-sjms2 (whose Sjms2Endpoint extends SjmsEndpoint) and through camel-amqp (whose AMQPJmsBinding extends JmsBinding), and by other JMS-family components built on JmsComponent such as camel-activemq and camel-activemq6. This issue affects Apache Camel: from 3.0.0 before 4.14.7, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.7. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-27); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
camel

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-26: 1Mentions · 2026-04-27: 2Mentions · 2026-05-05: 1Mentions · 2026-07-10: 1PoC Mentioned / Linked · 2026-07-10: 1Exploit Tool / Code · 2026-07-10: 1Technical Details · 2026-04-27: 2Technical Details · 2026-05-05: 1Technical Details · 2026-07-10: 104-2604-2705-0507-10
Signal classification3 categories
General
360.0%
Disclosure
120.0%
PoC
120.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-261
General1
2026-04-272
General2
2026-05-051
Disclosure1
2026-07-101
PoC1
Full discourse5 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-40860 PT ID: PT-2026-35372 Vendor: Apache Software Foundation Product: Apache Camel Description: JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or class denylist. Because this code path is reached whenever the mapJmsMessage option is enabled (the default) and Camel acts as a JMS consumer, an attacker able to publish a crafted ObjectMessage to a queue or topic consumed by a Camel application could achieve remote code execution when a deserialization gadget chain was present on the classpath. The same handling was reached transitively through camel-sjms2 (whose Sjms2Endpoint extends SjmsEndpoint) and through camel-amqp (whose AMQPJmsBinding extends JmsBinding), and by other JMS-family components built on JmsComponent such as camel-activemq and camel-activemq6. This issue affects Apache Camel: from 3.0.0 before 4.14.7, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-35372 • https://github.com/oscerd/CVE-2026-40860 #dbugs_vuln

    Post summary

    A Proof of Concept for CVE‑2026‑40860 demonstrates a deserialization‑based remote code execution flaw in Apache Camel’s JMS components, though no active exploitation or patch information is provided.

    00001543
    2.5K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-40860: Unsafe Deserialization of JMS ObjectMessage in Apache Camel - What It Means for Your Business and How to Respond https://hubs.li/Q04fs8Ly0

    Post summary

    The article announces CVE-2026‑40860 in Apache Camel, describing an unsafe deserialization issue with JMS ObjectMessage and outlining business implications and general response steps.

    0000043
    29 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40860 JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via jav… https://www.cve.org/CVERecord?id=CVE-2026-40860 ----- Traducción: CVE-2026-40860 Jms… http://infoflow.cloud`

    Post summary

    A brief disclosure of CVE‑2026‑40860 is provided, mentioning the affected classes and a link to the CVE record, but it lacks additional technical depth or evidence of exploitation.

    00000446
    72 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40860 JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via jav… https://www.cve.org/CVERecord?id=CVE-2026-40860

    Post summary

    The text briefly notes CVE‑2026‑40860, pointing out that camel‑jms and camel‑sjms deserialized JMS ObjectMessage payloads via Java deserialization, but offers no PoC, exploit code, patch, or evidence of active use.

    00000521
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40860 CVE-2026-40860 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40860 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post merely lists CVE-2026-40860 and links to a vulnerability portal, providing no additional context about exploits, patches, or status.

    0000042
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---
Appapachecamel4.19.0--

Explore more