CVE-2026-40860 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 27, 2026
Apache Camel - Remote Code Execution
Overview
Apache Camel 3.0.0 < 4.14.7, 4.15.0 < 4.18.2, and 4.19.0 < 4.20.0 contain a remote code execution vulnerability caused by unsafe deserialization of JMS ObjectMessage payloads without applying ObjectInputFilter or class allowlist/denylist, letting attackers publish crafted ObjectMessages to achieve remote code execution, exploit requires attacker to publish crafted JMS messages to a consumed queue or topic.
Severity & Score
Impact
Attackers can execute arbitrary code remotely by sending crafted JMS ObjectMessages to Camel consumers, potentially compromising the entire system.
Mitigation
Upgrade to Apache Camel 4.20.0, or 4.14.7 for 4.14.x LTS, or 4.18.2 for 4.18.x releases.
References
Related Resources
Details
- CVE ID
- CVE-2026-40860
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- insecure_deserialization
- Status
- unconfirmed
CWE
- CWE-502
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H