CVE-2026-49086 is an improper input-validation and confused-deputy vulnerability in Apache Camel's camel-dapr Dapr Pub/Sub consumer. The consumer copied the inbound CloudEvent Pub/Sub component name and topic into Exchange headers that are subsequently treated as producer-side routing overrides. When a route consumes a Dapr Pub/Sub message and republishes it through a Dapr producer, the producer configuration proxy prefers these attacker-controlled header values over the destination configured on the producer endpoint. An authorized publisher to the consumed topic can therefore cause republished messages to be sent to a Pub/Sub component and topic of the publisher's choosing. Affected versions are 4.12.0 through before 4.14.8, 4.15.0 through before 4.18.3, and 4.19.0 through before 4.21.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-49086 in Apache Camel's camel-dapr component. The repository contains a vulnerable Camel route, mock Dapr client implementations, and a web-accessible attacker driver. The core exploit path is in VictimRoutes.java and ExploitController.java: the route consumes from a Dapr pub/sub endpoint configured as orders-broker/orders and republishes to an intended fixed audit destination audit-broker/audit-log, while the controller forges inbound CloudEvent metadata so the vulnerable consumer copies attacker-controlled pubsubName/topic into Camel routing headers. Because the downstream producer prefers those headers over endpoint configuration, the republished message is redirected to attacker-selected destinations such as attacker-broker/exfil-secrets. Repository structure: Application.java boots the app; DaprMockConfig.java provides proxy-based mock DaprClient and DaprPreviewClient so no real Dapr sidecar is needed; SubscriptionRegistry.java captures the consumer listener; PublishRecorder.java records the actual publish target and payload; VictimRoutes.java defines the vulnerable subscribe-then-publish flow; ExploitController.java exposes GET /exploit/attack to trigger normal and malicious test events and print proof of exploitation. This is a real exploit/reproducer rather than a scanner: it demonstrates message redirection and data exfiltration via confused-deputy behavior in vulnerable Camel deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.