CVE-2026-46590General(apache / camel)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Deserialization of Untrusted Data vulnerability in Apache Camel PQC component. The camel-pqc component persists post-quantum key metadata (KeyMetadata) through pluggable KeyLifecycleManager implementations. HashicorpVaultKeyLifecycleManager and AwsSecretsManagerKeyLifecycleManager read that metadata back from the configured secret backend by deserializing a Base64-wrapped value with a raw java.io.ObjectInputStream.readObject() and no ObjectInputFilter or class allow-list; the cast to KeyMetadata happens only after readObject() returns, so any readObject() side effects in a crafted object run before the type check. The same unfiltered legacy-migration read also remained in FileBasedKeyLifecycleManager (for the stored KeyPair and KeyMetadata). A principal who can write to the operator-controlled backend that holds these values - the HashiCorp Vault KV path, or the AWS Secrets Manager secret (requiring a Vault token or secretsmanager:PutSecretValue) - could store a crafted serialized object that is deserialized during normal key-lifecycle operations, potentially leading to code execution in the context of the application that manages the keys. This is an incomplete-remediation follow-on to CVE-2026-40048 (CAMEL-23200), which changed FileBasedKeyLifecycleManager to store metadata as JSON / PKCS#8 / X.509 but did not add an ObjectInputFilter, did not cover the Vault and AWS sibling managers, and left FileBasedKeyLifecycleManager's own legacy-migration deserialization unfiltered. This issue affects Apache Camel: from 4.18.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.18.x LTS releases stream, then they are suggested to upgrade to 4.18.3. For deployments that cannot upgrade immediately, restrict write access to the key backend so that only the application's own identity can write the camel-pqc secrets (least-privilege HashiCorp Vault policies and secretsmanager:PutSecretValue IAM), and keep the PQC key material in a backend separate from any data that less-trusted principals can write.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-07-11); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-09: 1Mentions · 2026-07-11: 2Mentions · 2026-07-13: 1Mentions · 2026-07-15: 1PoC Mentioned / Linked · 2026-07-15: 1Exploit Tool / Code · 2026-07-15: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-11: 2Technical Details · 2026-07-15: 107-0907-1107-1307-15
Signal classification4 categories
General
240.0%
Patch
120.0%
Disclosure
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-091
Patch1
2026-07-112
Disclosure1General1
2026-07-131
General1
2026-07-151
PoC1
Full discourse5 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-46590 PT ID: PT-2026-55895 Vendor: Apache Software Foundation Product: Apache Camel Description: Deserialization of untrusted data in the Apache Camel PQC component occurs when HashicorpVaultKeyLifecycleManager, AwsSecretsManagerKeyLifecycleManager, and FileBasedKeyLifecycleManager read key metadata from secret backends. These components use http://java.io.ObjectInputStream.readObject() to deserialize Base64-wrapped values without an ObjectInputFilter or class allow-list. An attacker with write access to the HashiCorp Vault KV path or AWS Secrets Manager secret can store a crafted serialized object. When the application performs normal key-lifecycle operations, the object is deserialized, potentially leading to remote code execution in the application context. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55895 • https://github.com/oscerd/CVE-2026-46590 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑46590 has been identified, detailing deserialization RCE in Apache Camel, with code linked to GitHub; no active exploitation or patch information is reported.

    020911.6K
    3.4K followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「Apache Software FoundationのApache Camelにおける信頼できないデータのデシリアライゼーションに関する脆弱性(CVE-2026-46590)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ… ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post is a high‑level commentary on CVE‑2026‑46590, outlining its background, purpose, and impact, without providing technical or exploitation details.

    0000077
    840 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「Apache Software FoundationのApache Camelにおける信頼できないデータのデシリアライゼーションに関する脆弱性(CVE-2026-46590)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ… ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post provides a conceptual overview of CVE‑2026‑46590, outlining its background, purpose, and effect, but offers no proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    0000089
    840 followersView on X
  • ゆぅさん@YY20424277
    Disclosure

    【3軸解説】「Apache Software FoundationのApache Camelにおける信頼できないデータのデシリアライゼーションに関する脆弱性(CVE-2026-46590)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ… ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The article explains the background, purpose, and effect of CVE‑2026‑46590, identifying it as a deserialization flaw in Apache Camel, but offers no exploitation details, patch info, or evidence of active attacks.

    0000063
    840 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-46590 (CVSS 8.8) - Deserialization flaw in Apache Camel PQC component allows code execution. Affects v4.18.0-4.18.2 & 4.19.0-4.20.x. Upgrade to 4.21.0 or 4.18.3 immediately. #CVE #Vulnerability #PatchNow https://t.co/xtb9dsEeFK

    Post summary

    The tweet announces a high‑severity deserialization flaw in the Apache Camel PQC component and urges immediate upgrade to supported versions to mitigate the issue.

    0000045
    70 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more