CVE-2026-47323Disclosure(apache / camel)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHeaderFilterStrategy in camel-knative-http) only filter outbound Camel-internal headers via setOutFilterStartsWith, while not configuring inbound filtering via setInFilterStartsWith. As a result, an unauthenticated attacker can inject Camel-internal headers (e.g. CamelExecCommandExecutable, CamelFileName) via HTTP requests to CXF-RS or CXF-SOAP endpoints. When a route forwards messages from these endpoints to header-driven components such as camel-exec or camel-file, the injected headers override configured values, enabling remote code execution or arbitrary file writes. This is the same pattern that was previously addressed in camel-undertow (CVE-2025-30177), the broader incoming-header filter (CVE-2025-27636 and CVE-2025-29891), and non-HTTP strategies (CVE-2026-40453). This issue affects Apache Camel: from 3.18.0 before 4.14.6, from 4.15.0 before 4.18.2. Users are recommended to upgrade to version 4.19.0, which fixes the issue. If users are on the 4.18.x LTS releases stream, then they are suggested to upgrade to 4.18.2. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.6.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178CWE-791

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-19); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-19: 2Mentions · 2026-05-20: 1Mentions · 2026-07-17: 1PoC Mentioned / Linked · 2026-07-17: 1Exploit Tool / Code · 2026-07-17: 1Technical Details · 2026-05-19: 2Technical Details · 2026-05-20: 1Technical Details · 2026-07-17: 105-1905-2007-17
Signal classification2 categories
Disclosure
375.0%
Exploit
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-192
Disclosure2
2026-05-201
Disclosure1
2026-07-171
Exploit1
Full discourse4 posts
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-47323 PT ID: PT-2026-41898 Vendor: Apache Software Foundation Product: Apache Camel Description: An unauthenticated attacker can perform message header injection due to missing inbound filtering in the CxfRsHeaderFilterStrategy and Knative HeaderFilterStrategy implementations. This allows the injection of Camel-internal headers to override configured values, which can lead to remote code execution or arbitrary file writes. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-41898 • https://github.com/oscerd/CVE-2026-47323 #dbugs_vuln

    Post summary

    An exploit for CVE-2026-47323 was discovered through header injection in Apache Camel, with a PoC available on GitHub, although no active exploitation or patch information is provided.

    0001031.2K
    3.4K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-47323: Apache Camel: Camel-CXF Message Header Injection via Missing Inbound Filtering https://www.openwall.com/lists/oss-security/2026/05/19/13 unauthenticated attacker can inject Camel-internal headers [which] override configured values, enabling remote code execution or arbitrary file writes

    Post summary

    The text announces CVE-2026-47323, describing a header injection vulnerability in Apache Camel that can lead to remote code execution or file writes, with no PoC, exploit code, or patch details provided.

    10040510
    4.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-47323 Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrateg… https://www.cve.org/CVERecord?id=CVE-2026-47323 ----- Traducción: CVE-2026-47323 Iny… http://infoflow.cloud`

    Post summary

    The tweet simply announces CVE‑2026‑47323, describing it as a Message Header Injection issue in Camel‑CXF and Knative with no PoC, exploit code, or mitigation details provided.

    0000039
    78 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-47323 Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrateg… https://www.cve.org/CVERecord?id=CVE-2026-47323

    Post summary

    CVE-2026-47323 discloses a message header injection flaw in Camel-CXF and Camel-Knative due to missing inbound filtering, as outlined in the CVE record.

    00000237
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more