← Vulnerability feed

Vulnerability record · CVE-2018-11786 · published 18 September 2018

CVE-2018-11786: Apache karaf improper privilege management vulnerability

Apache · Karaf

In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user.

8.8 CVSS 3.0 High EPSS 1.9% · top 21.1% CWE-269 · Improper privilege management
8.8CVSS 3.0 base score, v2 9.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

In Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with rights to the Karaf console can pivot and read/write any file on the file system to which the Karaf process user has access. This can be locked down a bit by using chroot to change the root directory to protect files outside of the Karaf install directory; it can be further locked down by defining a security manager policy that limits file system access to those directories beneath the Karaf home that are necessary for the system to run. However, this still allows anyone with ssh access to the Karaf process to read and write a large number of files as the Karaf process user.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11786 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-40145Apache karaf improper input validation vulnerabilityThis vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function j…EPSS 2.4%9.8CVE-2018-11788Apache karaf xml external entity (xxe) vulnerabilityApache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The …EPSS 7.3%8.1CVE-2021-41766Apache karaf deserialization of untrusted data vulnerabilityApache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology…EPSS 2.0%8.1CVE-2020-28052Bouncycastle bc-java vulnerabilityAn issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data …EPSS 7.2%8.1CVE-2018-11787Apache karaf improper authentication vulnerabilityIn Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…EPSS 2.6%6.5CVE-2019-0191Apache karaf path traversal vulnerabilityApache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes …EPSS 4.9%6.5CVE-2016-8750Apache karaf ldap injection vulnerabilityApache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly a…EPSS 5.2%6.3CVE-2020-11980Apache karaf server-side request forgery (ssrf) vulnerabilityIn Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2018-11786), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.