CVE-2026-46591Patch(apache / camel)

MEDIUMCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Apache Camel Neo4J component. The camel-neo4j producer builds the Cypher WHERE clause for its match/retrieve and delete operations from the CamelNeo4jMatchProperties map. CVE-2025-66169 addressed Cypher injection through the property values by binding them as query parameters ($paramN), but the property names (the JSON keys of that map) were still concatenated into the query string verbatim in Neo4jProducer.retrieveNodes() and deleteNode(). A property name containing Cypher syntax therefore alters the structure of the executed query. Where a route maps untrusted input into the CamelNeo4jMatchProperties map - for example by passing a request body as the match map, or from a consumer that does not filter inbound Camel* headers - an attacker who controls the JSON key names can inject arbitrary Cypher and read, modify or delete any node or relationship in the Neo4j database. The CamelNeo4jMatchProperties header is itself Camel-prefixed and is filtered by the HTTP header-filter strategy, so a plain HTTP client cannot set it directly; the issue is reachable through routes that deliberately or inadvertently carry untrusted data into that header. This issue affects Apache Camel: from 4.10.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. For deployments that cannot upgrade immediately, do not populate the CamelNeo4jMatchProperties map from untrusted input: validate or allow-list the property names (for example against ^[A-Za-z_][A-Za-z0-9_]*$) before the Neo4j producer, and ensure that any consumer feeding such a route filters inbound Camel* / camel* headers so the match header cannot be supplied by an external sender.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-07-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-09: 1Mentions · 2026-07-16: 1PoC Mentioned / Linked · 2026-07-16: 1Exploit Tool / Code · 2026-07-16: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-16: 107-0907-16
Signal classification2 categories
Patch
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-091
Patch1
2026-07-161
PoC1
Full discourse2 posts
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-46591 PT ID: PT-2026-55896 Vendor: Apache Software Foundation Product: Apache Camel Description: An issue exists in the Apache Camel Neo4J component where the producer builds the Cypher WHERE clause for match, retrieve, and delete operations using the CamelNeo4jMatchProperties map. While property values are bound as parameters, the property names (JSON keys of the map) are concatenated directly into the query string within the retrieveNodes() and deleteNode() functions. This allows an attacker who can control the JSON key names to inject arbitrary Cypher syntax, potentially enabling them to read, modify, or delete any node or relationship in the Neo4J database. This is possible in routes that map untrusted input into the CamelNeo4jMatchProperties map or use consumers that do not filter inbound Camel headers. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55896 • https://github.com/oscerd/CVE-2026-46591 #dbugs_vuln

    Post summary

    PoC and exploit code for CVE-2026-46591 are publicly available with technical details, but no evidence of active exploitation or a patch.

    00012619
    2.5K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2026-46591 (CVSS 8.2) - Cypher injection in Apache Camel Neo4J component allows attackers to read/modify/delete database nodes. Affects versions 4.10.0-4.14.7, 4.15.0-4.18.2, 4.19.0-4.20.x. Patch now! #CVE #PatchNow https://t.co/UB3x6Kadyt

    Post summary

    High‑severity CVE‑2026‑46591 involves a Cypher injection in the Apache Camel Neo4J component, allowing CRUD operations on database nodes. A patch is available for affected versions.

    0000051
    70 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more