CVE-2026-40022
Apache Software Foundation Apache Camel Platform HTTP Main, Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14, OpenShift Serverless
When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthenticationConfigurer and JWTAuthenticationConfigurer classes derive the authentication path from properties.getPath() when camel.server.authenticationPath / camel.management.authenticationPath is not explicitly set. Combined with the Vert.x sub-router mounting model - the sub-router is mounted at _path_* and the authentication handler is re...
- CVSS
- 8.2
- EPSS
- 0.62% 46.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.27