CVE-2026-46592 is an improper input validation and confused-deputy vulnerability in Apache Camel's CXF SOAP component. In vulnerable releases, the CXF producer determines the backend SOAP operation from operation-selection Exchange headers. Those headers used non-Camel-prefixed names and therefore were not removed by the HTTP header filter strategy at a transport boundary. An untrusted HTTP request entering a route that bridges an HTTP consumer to a CXF producer can supply these headers and cause the producer to resolve and invoke a backend WSDL operation different from the operation intended by the route. The shared CXF common module also exposed the non-prefixed operation-selection names to camel-cxfrs.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-46592, a header-injection/confused-deputy issue in Apache Camel's camel-cxf component. The exploit demonstrates that when an HTTP-facing Camel route forwards requests into a cxf: producer on affected versions, an attacker can supply the non-Camel-prefixed control header operationName and override the route's intended default SOAP operation. Repository structure is small and focused: Application.java starts the Spring Boot app; SoapBackend.java publishes a real CXF SOAP service at http://localhost:9000/account; AccountService.java and AccountServiceImpl.java define two backend operations, benign getBalance and destructive deleteAccount; VictimRoute.java exposes platform-http:/api and forwards requests to the SOAP backend with defaultOperationName=getBalance; ExploitController.java acts as an attacker harness and issues both a legitimate request and a malicious request with operationName=deleteAccount to prove operation redirection. Supporting files include pom.xml with Camel 4.18.2 and CXF dependencies, application.properties setting port 8080, and Docker artifacts for containerized execution. Main exploit capability: remote web/network abuse of a bridging route to change which backend SOAP method is invoked, without needing code execution or deserialization. The provided payload is simple but functional: POST to /api with body acct-001 and header operationName: deleteAccount. Successful exploitation causes the backend to execute deleteAccount instead of getBalance, deleting the sample account and setting an internal flag used for verification. This is an operational PoC rather than a weaponized framework module: it contains a working exploit path and demonstration harness, but payload customization is minimal and tightly scoped to the sample service. Fingerprintable targets and observables include the victim HTTP endpoint on 127.0.0.1:8080/api, the demonstration endpoint /exploit/attack on port 8080, the backend SOAP service at localhost:9000/account, and the critical attacker-controlled header operationName. The exploit is not merely a detector; it actively triggers the vulnerable behavior and demonstrates destructive backend impact.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A header-manipulation vulnerability in Apache Camel CXF SOAP that can let a remote attacker execute unintended operations.
An Apache Camel CXF SOAP vulnerability that permits a remote attacker to execute unintended operations through header manipulation.
An improper-input-validation/confused-deputy vulnerability in Apache Camel CXF SOAP and REST components. In HTTP-to-CXF bridging routes, attacker-controlled operationName and operationNamespace HTTP headers could pass the HTTP header filter and cause the CXF producer to invoke a different backend WSDL SOAP operation, potentially substituting a destructive operation for the route's intended operation. Unauthenticated exploitation is possible where the bridging HTTP consumer is unauthenticated.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.