CVE-2026-46592
Last modified
CVE-2026-46592 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName (and operationNamespace) Exchange header, whose constant values (CxfConstants.OPERATION_NAME / OPERATION_NAMESPACE) were the plain strings operationName / operationNamespace. Because these names do not start with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel header namespace on the HTTP boundary - let them pass from an inbound HTTP request straight into the Exchange. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel CXF SOAP component. The camel-cxf producer selects which SOAP operation to invoke on the backend service from the operationName (and operationNamespace) Exchange header, whose constant values (CxfConstants.OPERATION_NAME / OPERATION_NAMESPACE) were the plain strings operationName / operationNamespace. Because these names do not start with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel header namespace on the HTTP boundary - let them pass from an inbound HTTP request straight into the Exchange. In a route that bridges an HTTP consumer (for example platform-http) into a cxf: producer, any HTTP client could therefore set the operationName header and have CxfProducer resolve and invoke a different WSDL operation than the route intended - for example replacing a read operation with a destructive one - against the backend SOAP service (a confused-deputy redirection). The constant is defined in the shared camel-cxf-common module, so the same non-prefixed names also applied to camel-cxfrs. No credentials are required when the bridging consumer is unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. After upgrading, the operation-selection headers are named CamelCxfOperationName / CamelCxfOperationNamespace and are filtered at transport boundaries; see the 4.21 upgrade guide for the cross-transport carrier-header pattern. For deployments that cannot upgrade immediately, do not select the CXF operation from untrusted input: strip the operationName and operationNamespace headers from any untrusted ingress before the cxf: producer and set the operation from a trusted source in the route.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Camel | >= 4.0.0, < 4.14.8 |
| Apache | Camel | >= 4.15.0, < 4.18.3 |
| Apache | Camel | >= 4.19.0, < 4.21.0 |
References
- https://camel.apache.org/security/CVE-2026-46592.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/07/05/15Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-46592?
How severe is CVE-2026-46592?
How do I fix CVE-2026-46592?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-46586Improper Control of Generation of Code ('Code Injection'), I…8.8
- CVE-2026-46587Improper Input Validation vulnerability in Apache Camel. Th…7.3
- CVE-2026-46588Improper Input Validation vulnerability in Apache Camel. Th…7.3
- CVE-2026-4659The Unlimited Elements for Elementor plugin for WordPress is…7.5
- CVE-2026-46590Deserialization of Untrusted Data vulnerability in Apache Ca…8.8
- CVE-2026-46591Improper Neutralization of Special Elements in Data Query Lo…8.2
- CVE-2026-46593A SQL injection vulnerability has been identified in the PHP…8.6
- CVE-2026-46594A reflected cross-site scripting (XSS) vulnerability has bee…5.1
- CVE-2026-46595Previously, CVE-2024-45337 fixed an authorization bypass for…10
- CVE-2026-46597An incorrectly placed cast from bytes to int allowed for ser…7.5
- CVE-2026-46598For certain crafted inputs, a 'ed25519.PrivateKey' was creat…5.3
- CVE-2026-46599The TIFF decoder does not place a limit on the size of PackB…7.5
Are you affected by CVE-2026-46592?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
