This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q8ch-jx67-q52x | Apache Camel K: Kubernetes namespace authorized users can create a Build resource |
Sat, 23 May 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 22 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache camel |
|
| Vendors & Products |
Apache
Apache camel |
Thu, 21 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 21 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | (Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can create a Build resource, controlling the Pod generation in a namespace of their choice, including the operator namespace. This issue affects Apache Camel K: from 2.0.0 before 2.8.1, from 2.9.0 before 2.9.2, from 2.10.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1 (or 2.8.1 or 2.9.2), which fixes the issue. | |
| Title | Apache Camel K: Camel K Cross-Namespace Build Deputy Attack | |
| Weaknesses | CWE-610 CWE-639 |
|
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-05-23T02:17:48.106Z
Reserved: 2026-05-13T07:38:04.636Z
Link: CVE-2026-45760
Updated: 2026-05-23T02:17:43.097Z
Status : Deferred
Published: 2026-05-21T13:16:19.840
Modified: 2026-06-17T10:52:32.097
Link: CVE-2026-45760
No data.
OpenCVE Enrichment
Updated: 2026-05-23T04:30:09Z
Github GHSA