CVE-2026-66908: CWE-287 Improper Authentication in Apache Software Foundation Apache Camel
Description
CVE-2026-66908 is an improper authentication vulnerability in the Apache Camel Platform HTTP Main component affecting versions from 4.8.0 up to but not including 4.22.0. The issue arises because the JWT authentication configuration does not enforce validation of the issuer (iss) and audience (aud) claims unless explicitly configured, allowing acceptance of any unexpired token signed by a trusted key. This can lead to acceptance of tokens intended for other services or audiences within the same trust domain. The vulnerability is fixed in version 4.22.0, which requires explicit configuration of issuer and audience claims or an explicit override to allow missing claims. Users on maintenance branches 4.14.x and 4.18.x should upgrade to versions 4.14.9 or 4.18.4 and configure these claims accordingly.
CVSS v3.1
Score 7.5high
Affected software
Apache Software Foundation
Apache Camel
pkg:maven/Apache Software Foundation/org.apache.camel:camel-platform-http-mainRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Apache Camel's embedded HTTP server component improperly authenticates JWT tokens by not validating the issuer and audience claims unless these are explicitly configured via jwtIssuer and jwtAudience options introduced in version 4.21.0. Prior to 4.22.0, if these options are not set, the server only checks token signature and expiry, accepting any token signed by a trusted key regardless of issuer or intended audience. This flaw affects versions from 4.8.0 before 4.22.0. Version 4.22.0 fixes the issue by refusing to start if a JWT keystore is configured without jwtIssuer or jwtAudience set, unless the new jwtAllowMissingIssuerAndAudience option is explicitly enabled. Maintenance releases 4.14.9 and 4.18.4 add the options but do not enforce them by default. The vulnerability allows tokens issued for other services or audiences within the trust domain to be accepted, potentially leading to unauthorized access. Operators are advised to restrict the JWT keystore to the smallest trust set possible and ensure front-end gateways validate issuer and audience claims to prevent bypass.
Potential Impact
The vulnerability allows acceptance of any unexpired JWT token signed by a key trusted by the configured keystore, regardless of the token's issuer or intended audience. This can lead to unauthorized access to the affected Apache Camel HTTP endpoints if tokens issued for other services or audiences within the same trust domain are presented. The impact depends on the trust scope of the keystore's signing keys. There is no indication of confidentiality or availability impact beyond improper authentication. No known exploits in the wild have been reported.
Mitigation Recommendations
Users should upgrade to Apache Camel version 4.22.0 or later, which enforces validation of issuer and audience claims or requires explicit configuration to allow missing claims. For users on maintenance branches 4.14.x or 4.18.x, upgrade to versions 4.14.9 or 4.18.4 and configure jwtIssuer, jwtAudience, or both to enforce claim validation. Independently of version, restrict the JWT keystore to the smallest possible trust set, ideally a dedicated signer for the service, and ensure any front-end gateway performing issuer and audience validation cannot be bypassed. Note that versions prior to 4.21.0 do not support enforcing these claims and should be upgraded to a version that does.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-07-28T09:33:04.800Z
- State
- PUBLISHED
Threat ID: 6a8c7117acd9273b49d27da7
Added to database: 08/24/2026, 16:28:07 UTC
Last enriched: 09/10/2026, 10:07:48 UTC
Last updated: 10/08/2026, 18:48:47 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.