CVE-2026-49099 is an authorization-bypass and injection vulnerability in the Apache Camel Salesforce component. The Salesforce producer resolves operation parameters from Exchange headers in preference to endpoint-configured values. Vulnerable releases use non-Camel-prefixed header names for Salesforce controls, allowing those headers to pass through the HTTP header filtering boundary into an Exchange. In an HTTP-consumer-to-Salesforce-producer route, an untrusted client can override SOQL or SOSL queries, target SObject names and identifiers, and Apex REST URLs, methods, and query parameters. Affected versions are Apache Camel 4.0.0 through before 4.14.8, 4.15.0 through before 4.18.3, and 4.19.0 through before 4.21.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a self-contained Java/Spring Boot proof-of-concept reproducer for CVE-2026-49099 in Apache Camel's camel-salesforce component. It is a real exploit demonstration, not merely a detector: the app exposes a victim HTTP route and an attacker route, then programmatically sends a POST request with a malicious sObjectQuery header to prove that inbound HTTP headers can override the Salesforce producer's configured query. Repository structure is small and focused: Application.java starts the Spring Boot app; VictimRoute.java defines the vulnerable Camel route from platform-http:/contacts to salesforce:query with a supposedly fixed account-scoped SOQL query; ExploitController.java drives the attack by calling /contacts once normally and once with an injected sObjectQuery header; SoqlRecorder.java stores the actual SOQL executed; RecordingSalesforceComponent.java replaces the real Salesforce transport with a mock RestClient so the vulnerable Camel processor logic runs unchanged without requiring a Salesforce org, OAuth, or external network; SalesforceConfig.java registers that mock salesforce component with lazyLogin enabled. Supporting files include pom.xml, Dockerfile, docker-compose.yml, and application.properties. Main exploit capability: HTTP header injection into Camel exchange headers to override Salesforce operation parameters. The implemented PoC specifically demonstrates SOQL query override/broken access control by replacing "SELECT Id, Name FROM Contact WHERE AccountId = '001XXXXXXXXXXXXXXX'" with "SELECT Id, Name, Email, Phone, MailingStreet FROM Contact". The README indicates the same primitive can also affect SOSL searches, SObject CRUD targets, and Apex REST URL/method/query parameters via related headers. The exploit targets affected camel-salesforce versions, especially the pinned vulnerable dependency 4.18.2 in pom.xml. Fingerprintable endpoints are primarily local web endpoints and Camel URIs: /exploit/attack triggers the demonstration, /contacts is the victim route, and the internal Camel producer URI is salesforce:query?... with a configured sObjectQuery. The code also contains a placeholder Salesforce login URL https://login.invalid, but it is intentionally unused. Overall maturity is OPERATIONAL because the exploit is fully runnable and demonstrates successful parameter override, though it uses a fixed local payload and mock backend rather than a generalized framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.