CVE-2026-46453 is an improper input-validation and authorization-bypass flaw in Apache Camel's camel-elasticsearch-rest-client component. Exchange headers controlling Elasticsearch query bodies, operations, index selection and settings, and document IDs were defined with unprefixed values. Camel's inbound HTTP header filter blocks headers prefixed with Camel or camel, so these control headers could pass from an HTTP request into a route unchanged. In a route where an HTTP consumer forwards to an elasticsearch-rest-client producer, the producer consumes the attacker-supplied control headers unconditionally, allowing the requester to override behavior configured by the route author.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working Java/Spring Boot reproducer for CVE-2026-46453, an Apache Camel camel-elasticsearch-rest-client header-injection vulnerability. It is not merely documentation: it contains a runnable victim route, a local exploit trigger, and Elasticsearch seeding logic to demonstrate unauthorized data exposure. Structure and purpose: - Application.java starts the Spring Boot app. - VictimRoute.java defines the vulnerable Camel route: platform-http:/products forwards requests to an elasticsearch-rest-client producer configured for GET_BY_ID on the products index. - ExploitController.java acts as the attacker. Its /exploit/attack endpoint sends two requests to the victim route: a benign request with header ID: public-1 and a malicious request with injected headers OPERATION: SEARCH and SEARCH_QUERY: {"query":{"match_all":{}}}. It compares responses to prove secret data leakage. - EsSeeder.java connects to Elasticsearch and seeds the products index with one public and one secret document, ensuring exploitation has observable impact. - docker-compose.yml launches Elasticsearch 8.15.3 with security disabled and port 9200 exposed. - application.properties binds the app to port 8080. - pom.xml pins Camel to vulnerable version 4.18.2 and includes camel-platform-http and camel-elasticsearch-rest-client dependencies. Main exploit capability: The exploit abuses unprefixed Camel exchange header names used by camel-elasticsearch-rest-client (notably OPERATION, SEARCH_QUERY, INDEX_NAME, INDEX_SETTINGS, ID). Because platform-http's default inbound HttpHeaderFilterStrategy only blocks Camel*/camel* headers, attacker-supplied HTTP headers pass through unchanged. The Elasticsearch producer then honors these headers over the route's intended configuration. In the provided demo, this changes the route from a safe single-document GET_BY_ID into a SEARCH that returns the full index, including a secret record. The README also notes the same primitive could enable other unauthorized operations such as deleting documents. Overall, this is an operational local lab reproducer for a web/network attack vector against exposed Camel HTTP routes fronting Elasticsearch producers on affected versions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.