CVE-2026-46590 is an unsafe Java deserialization vulnerability in Apache Camel's camel-pqc component. HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize Base64-encoded persisted KeyMetadata using ObjectInputStream.readObject() without an ObjectInputFilter or class allow-list. The legacy-migration deserialization in the file-based key-lifecycle manager is likewise unfiltered for persisted key and metadata objects. Because type validation occurs only after readObject() returns, attacker-controlled deserialization side effects can execute before the object is cast to the expected type. The issue is an incomplete remediation follow-on to CVE-2026-40048 and affects Apache Camel 4.18.0 through 4.18.2 and 4.19.0 through 4.20.x.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept exploit for Apache Camel camel-pqc unsafe deserialization, CVE-2026-46590. It is not part of a common exploit framework. The repo contains a minimal web application that exposes a single GET endpoint, /exploit/attack, which demonstrates exploitation against FileBasedKeyLifecycleManager in vulnerable camel-pqc versions (camel.version pinned to 4.18.2 in pom.xml). Structure and purpose: Application.java is the Spring Boot entry point. ExploitController.java contains the main exploit flow: it creates a temporary key directory, writes an attacker-controlled legacy serialized key file named victim-key.key, instantiates FileBasedKeyLifecycleManager on that directory, and calls manager.getKey("victim-key"). Because the vulnerable manager migrates legacy .key files using raw ObjectInputStream.readObject() without an ObjectInputFilter, the malicious object is deserialized before the KeyPair cast fails. Gadget.java builds the CommonsCollections6 gadget chain using commons-collections 3.2.1 and reflection into java.util internals. application.properties configures the app to listen on port 8080. Dockerfile and docker-compose.yml provide a reproducible containerized environment. Main exploit capability: arbitrary command execution during deserialization, provided the attacker can write to the key backend used by FileBasedKeyLifecycleManager. The PoC uses a benign hardcoded payload, /usr/bin/touch /tmp/pwned, and then checks for the existence of /tmp/pwned as proof of execution. The exploit is operational rather than weaponized because the payload is hardcoded and the app is purpose-built for demonstration. Attack path: this is primarily a local/file-based exploit condition against the target application's key storage, wrapped in a web-triggerable demo interface. The attacker-controlled input is the planted legacy .key file; the victim action is a routine getKey() call. The exposed HTTP endpoint is only for triggering the demonstration in the PoC environment, not the underlying vulnerability itself. Notable targeting details: README states affected versions are 4.18.0 before 4.18.3 and 4.19.0 before 4.21.0. It also references related incomplete remediation history (CVE-2026-40048) and a sibling AWS Secrets Manager issue (CVE-2026-43867), but the implemented code specifically targets the file-based manager path.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unsafe Java deserialization vulnerability in Apache Camel's camel-pqc component. Unfiltered deserialization of persisted key metadata in HashiCorp Vault, AWS Secrets Manager, and legacy FileBasedKeyLifecycleManager paths can allow code execution when an attacker has write access to the relevant key backend.
A related independently reported incomplete-remediation follow-on for the same unsafe deserialization defect in Apache Camel PQC key-lifecycle manager code paths; it additionally covers HashiCorp Vault and file-based sibling managers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.