CVE-2026-46587 is an improper input validation vulnerability in the Apache Camel Couchbase component. Non-Camel-prefixed Exchange headers can bypass HeaderFilterStrategy protections, allowing externally controlled input to override the Couchbase operation selected by an affected Camel integration. Apache Camel versions through 4.14.7, 4.15.0 through 4.18.2, and 4.19.0 through 4.20.0 are affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working Java/Spring Boot proof-of-concept reproducer for CVE-2026-46587, a header-injection flaw in Apache Camel's camel-couchbase component. The exploit is not a standalone remote shell or malware payload; instead, it demonstrates that an unauthenticated HTTP client can influence backend Couchbase operations by supplying unprefixed CCB_* headers that bypass Camel's normal Camel* HTTP header filtering. Repository structure is small and purpose-built: Application.java starts the Spring Boot app; VictimRoute.java defines the vulnerable Camel routes exposed at platform-http:/save and platform-http:/fetch; ExploitController.java acts as the attacker client and automatically exercises the bug; CouchbaseHarness.java seeds and verifies database state directly through the Couchbase SDK; CouchbaseSettings.java centralizes host, credentials, bucket, and document IDs; docker-compose.yml provisions Couchbase Server 7.6.2 plus the app; Dockerfile packages the app; README.md documents the vulnerability, affected versions, and reproduction steps. Main exploit capability: ExploitController sends HTTP requests to /fetch and /save with injected CCB_ID and CCB_TTL headers. VictimRoute removes only Camel* headers, then defaults CCB_ID only if absent. Because CCB_ID and CCB_TTL are not Camel-prefixed, they survive the HTTP boundary and are consumed by camel-couchbase. This allows three demonstrated impacts: 1) disclosure by fetching system-config instead of the intended user-draft document, 2) tampering by overwriting system-config through the save route, and 3) data destruction by forcing TTL=1 on the caller's document so it expires shortly after being saved. The exploit targets Apache Camel camel-couchbase affected versions 4.0.0 before 4.14.8, 4.15.0 before 4.18.3, and 4.19.0 before 4.21.0. The included pom.xml pins Camel 4.18.2, an affected version. The PoC is operational because it includes runnable attack logic and a reproducible environment, but the payload is basic and hardcoded rather than framework-driven or highly customizable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.