CVE-2026-53913Disclosure(apache / camel)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch apache camel systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence: it rejects a request that carries no access token, then - only if requiredRoles is non-empty - validates the roles, and - only if requiredPermissions is non-empty - validates the permissions. The actual cryptographic verification of the bearer access token (signature, issuer and expiry for a local JWT, or active-state and issuer for token introspection) is performed exclusively inside those role and permission checks. KeycloakSecurityPolicy defaults requiredRoles and requiredPermissions to empty - which is the documented 'Basic Setup' - so on a route configured that way the role and permission checks are skipped and the access token is therefore never verified. The token-presence check still rejects a missing token, but an invalid token is accepted: any non-null value in the Authorization: Bearer header - including an arbitrary string or a forged, unsigned JWT - passes the policy and the request reaches the protected route, with no signature, issuer or expiry check and no request to Keycloak. The token is read from the inbound request header because allowTokenFromHeader defaults to true. Because the normal reason to place a route behind this policy is that the route performs server-side work, the bypass results in unauthenticated access to that work; where the protected route forwards to a code-execution-capable producer, it can result in unauthenticated remote code execution. This defect is independent of CVE-2026-23552: that issue concerned the issuer claim and was fixed by adding a check inside the verification routine, but here the verification routine is not reached at all in the default configuration, so the defect remains. This issue affects Apache Camel: from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. For deployments that cannot upgrade immediately, configure a non-empty requiredRoles or requiredPermissions on every KeycloakSecurityPolicy so that the token-verification path is exercised, set allowTokenFromHeader to false where the token is not expected from the request header, or perform token verification at the framework layer ahead of the policy.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-306CWE-636

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • camel

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-21)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
camel

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-07: 1Mentions · 2026-07-09: 1Mentions · 2026-07-21: 2PoC Mentioned / Linked · 2026-07-21: 2Exploit Tool / Code · 2026-07-21: 2Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-09: 1Technical Details · 2026-07-21: 207-0707-0907-21
Signal classification4 categories
Disclosure
125.0%
Patch
125.0%
Exploit
125.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-071
Disclosure1
2026-07-091
Patch1
2026-07-212
Exploit1PoC1
Full discourse4 posts
  • ThreatWire@ThreatWire_
    PoC

    🚨 A public PoC has been released for CVE-2026-53913 affecting Apache Camel Keycloak. The flaw allows authentication bypass due to improper token validation and may lead to unauthenticated RCE on vulnerable deployments. 🔗 https://github.com/oscerd/cve-2026-53913 #ApacheCamel #Keycloak #RCE

    Post summary

    A public PoC demonstrating an authentication bypass that can lead to unauthenticated RCE for CVE‑2026‑53913 has been published, with a GitHub link provided.

    00021164
    1.4K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-53913 PT ID: PT-2026-55908 Vendor: Apache Software Foundation Product: Apache Camel Keycloak Description: Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence: it rejects a request that carries no access token, then - only if requiredRoles is non-empty - validates the roles, and - only if requiredPermissions is non-empty - validates the permissions. The actual cryptographic verification of the bearer access token (signature, issuer and expiry for a local JWT, or active-state and issuer for token introspection) is performed exclusively inside those role and permission checks. KeycloakSecurityPolicy defaults requiredRoles and requiredPermissions to empty - which is the documented 'Basic Setup' - so on a route configured that way the role and permission checks are skipped and the access token is therefore never verified. The token-presence check still rejects a missing token, but an invalid token is accepted: any non-null value in the Authorization: Bearer header - including an arbitrary string or a forged, unsigned JWT - passes the policy and the request reaches the protected route, with no signature, issuer or expiry check and no request to Keycloak. The token is read from the inbound request header because allowTokenFromHeader defaults to true. Because the normal reason to place a route behind this policy is that the route performs server-side work, the bypass results in unauthenticated access to that work; where the protected route forwards to a code-execution-capable producer, it can result in unauthenticated remote code execution. This defect is independent of CVE-2026-23552: that issue concerned the issuer claim and was fixed by adding a check inside the verification routine, but here the verification routine is not reached at all in the default configuration, so the defect remains. This issue affects Apache Camel: from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-55908 • https://github.com/oscerd/cve-2026-53913 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploitation vector for CVE‑2026‑53913 has been released, detailing an authentication bypass in Apache Camel Keycloak that could allow unauthenticated remote code execution; no active exploitation or patch has yet been reported.

    00030765
    3.4K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-53913 (CVSS 9.8) - Apache Camel Keycloak Component authentication bypass. Default config accepts ANY bearer token—even forged JWTs—enabling unauthenticated RCE. Upgrade to 4.21.0 or 4.18.3 NOW. #CVE #PatchNow #ThreatIntel https://t.co/YuUYOFnfOe

    Post summary

    A critical authentication bypass in Apache Camel Keycloak (CVE‑2026‑53913) allows unauthenticated RCE; immediate upgrade to 4.21.0 or 4.18.3 is recommended.

    0000093
    70 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    🔓 Apache Camel's KeycloakSecurityPolicy never verifies bearer tokens in its default config. Any non-null token passes. CVE-2026-53913 is CVSS 9.8 critical. Check your camel-keycloak setup now. #ApacheCamel #infosec https://secalerts.co/vulnerability/CVE-2026-53913?utm_campaign=x https://t.co/DoI1y2MdWt

    Post summary

    The tweet highlights a critical flaw in Apache Camel’s KeycloakSecurityPolicy that allows any non‑null bearer token to bypass verification (CVE‑2026‑53913, CVSS 9.8).

    0000083
    852 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachecamel---

Explore more