CVE-2026-48206 is an improper input-validation and authorization-bypass vulnerability in Apache Camel's camel-jira component. JIRA producer operation parameters are read from Exchange headers, but several legacy control-header names were not Camel-prefixed. Consequently, Apache Camel's HTTP header filtering did not remove them at an HTTP ingress boundary. In a route connecting an HTTP consumer to a jira: producer, an untrusted client can supply these headers to override route-intended JIRA operation parameters. The JIRA action is performed using the credentials configured on the endpoint's service account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-48206 in Apache Camel's camel-jira component. It demonstrates a web-to-backend header injection flaw where non-Camel-prefixed control headers such as IssueKey pass through the HTTP boundary and are consumed by camel-jira producers as trusted operation parameters. Repository structure is small and focused: Application.java is the Spring Boot entry point; VictimRoute.java defines the vulnerable Camel route from platform-http:/deleteMyDraft to jira:deleteIssue with hardcoded service-account credentials and a default IssueKey of DRAFT-1; MockJiraController.java emulates a JIRA REST API under /rest/** and records which issue key was deleted; ExploitController.java is an attacker driver exposing /exploit/attack, which first sends a benign request and then repeats it with IssueKey: PROD-999 to prove arbitrary issue deletion. Supporting files include pom.xml with Camel 4.18.2 and Spring Boot dependencies, Dockerfile and docker-compose.yml for containerized execution, and application.properties for port/runtime settings. Main exploit capability: an attacker-controlled HTTP header overrides the intended JIRA issue key, causing the backend jira:deleteIssue producer to delete an arbitrary issue using the configured service account. The README also documents broader impact across other camel-jira operations, including create, transition, update, watcher management, linking, and work-log manipulation via other injectable headers. This is a real exploit PoC rather than a detector: it actively triggers the vulnerable route and verifies the backend action through the mock JIRA endpoint.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.