VYPR

pax-jdbc-config

by Apache

CVEs (1)

  • CVE-2026-91048Sep 29, 2026
    risk 0.00cvss —epss —

    The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFactoryImpl) treats a command with no matching ACL rule as allowed, so any authenticated shell session (including one holding only the viewer role) could run…