
A PoC/exploit has been discovered for vulnerability CVE-2026-46590 PT ID: PT-2026-55895 Vendor: Apache Software Foundation Product: Apache Camel Description: Deserialization of untrusted data in the Apache Camel PQC component occurs when HashicorpVaultKeyLifecycleManager, AwsSecretsManagerKeyLifecycleManager, and FileBasedKeyLifecycleManager read key metadata from secret backends. These components use http://java.io.ObjectInputStream.readObject() to deserialize Base64-wrapped values without an ObjectInputFilter or class allow-list. An attacker with write access to the HashiCorp Vault KV path or AWS Secrets Manager secret can store a crafted serialized object. When the application performs normal key-lifecycle operations, the object is deserialized, potentially leading to remote code execution in the application context. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55895 • https://github.com/oscerd/CVE-2026-46590 #dbugs_vuln
Post summary
A proof‑of‑concept exploit for CVE‑2026‑46590 has been identified, detailing deserialization RCE in Apache Camel, with code linked to GitHub; no active exploitation or patch information is reported.


