← Vulnerability feed

Vulnerability record · CVE-2021-41766 · published 26 January 2022

CVE-2021-41766: Apache karaf deserialization of untrusted data vulnerability

Apache · Karaf

Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder).

8.1 CVSS 3.1 High EPSS 2.0% · top 19.7% CWE-502 · Deserialization of untrusted data
8.1CVSS 3.1 base score, v2 6.8
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Apache Karaf allows monitoring of applications and the Java runtime by using the Java Management Extensions (JMX). JMX is a Java RMI based technology that relies on Java serialized objects for client server communication. Whereas the default JMX implementation is hardened against unauthenticated deserialization attacks, the implementation used by Apache Karaf is not protected against this kind of attack. The impact of Java deserialization vulnerabilities strongly depends on the classes that are available within the targets class path. Generally speaking, deserialization of untrusted data does always represent a high security risk and should be prevented. The risk is low as, by default, Karaf uses a limited set of classes in the JMX server class path. It depends of system scoped classes (e.g. jar in the lib folder).

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-41766 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-40145Apache karaf improper input validation vulnerabilityThis vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function j…EPSS 2.4%9.8CVE-2018-11788Apache karaf xml external entity (xxe) vulnerabilityApache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The …EPSS 7.3%8.8CVE-2018-11786Apache karaf improper privilege management vulnerabilityIn Apache Karaf prior to 4.2.0 release, if the sshd service in Karaf is left on so an administrator can manage the running instance, any user with ri…EPSS 1.9%8.1CVE-2020-28052Bouncycastle bc-java vulnerabilityAn issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data …EPSS 7.2%8.1CVE-2018-11787Apache karaf improper authentication vulnerabilityIn Apache Karaf version prior to 3.0.9, 4.0.9, 4.1.1, when the webconsole feature is installed in Karaf, it is available at .../system/console and re…EPSS 2.6%6.5CVE-2019-0191Apache karaf path traversal vulnerabilityApache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes …EPSS 4.9%6.5CVE-2016-8750Apache karaf ldap injection vulnerabilityApache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not encoding usernames properly a…EPSS 5.2%6.3CVE-2020-11980Apache karaf server-side request forgery (ssrf) vulnerabilityIn Karaf, JMX authentication takes place using JAAS and authorization takes place using ACL files. By default, only an "admin" can actually invoke on…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2021-41766), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.