New Apache Camel K Flaw (CVE-2026-45760) Enables Cross-Namespace Attacks
ID: 01d6d006-f142-5ae0-8929-63cffbb6fead
STIX ID: report--01d6d006-f142-5ae0-8929-63cffbb6fead
Feed Name: securityonline.info
Threat Score
A newly disclosed "Important" severity vulnerability (CVE-2026-45760) in Apache Camel K enables a cross-namespace "Build Deputy" attack via an authorization bypass using a user-controlled key, allowing an authorized user in one namespace to create malicious Build resources and hijack Pod creation in other namespaces (including operator namespaces); several version ranges are affected and patched releases have been published—administrators should upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
