CVE-2026-49099 Vulnerability Analysis & Exploit Details

CVE-2026-49099
Vulnerability Scoring

5.3
/10
Significant Risk

Security assessments indicate that CVE-2026-49099 presents a notable risk, potentially requiring prompt mitigation.

Attack Complexity Details

  • Attack Complexity: Low
    Exploits can be performed without significant complexity or special conditions.
  • Attack Vector: Network
    Vulnerability is exploitable over a network without physical access.
  • Privileges Required: None
    No privileges are required for exploitation.
  • Scope: Unchanged
    Exploit remains within the originally vulnerable component.
  • User Interaction: None
    No user interaction is necessary for exploitation.

CVE-2026-49099 Details

Status: Analyzed

Last updated: 🕒 08 Jul 2026, 03:10 UTC
Originally published on: 🕘 06 Jul 2026, 09:16 UTC

Time between publication and last update: 1 days

CVSS Release: version 3

CVSS3 Source

134c704f-9b21-4f2e-91b3-4a467353bcc0

CVSS3 Type

Secondary

CVSS3 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE-2026-49099 Vulnerability Summary

CVE-2026-49099: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel Salesforce Component. The camel-salesforce producer resolves its operation parameters - the SOQL query, the SOSL search, the target SObject name and id, the Apex REST URL and method, and the Apex query parameters - from Exchange message headers, reading the header in preference to the value configured on the endpoint (AbstractSalesforceProcessor.getParameter() reads the header first and uses the endpoint configuration only as a fallback). The control-header constants in SalesforceEndpointConfig (for example SOBJECT_QUERY = sObjectQuery, SOBJECT_SEARCH = sObjectSearch, SOBJECT_NAME = sObjectName, SOBJECT_ID = sObjectId, APEX_URL = apexUrl, APEX_METHOD = apexMethod, and the apexQueryParam. prefix) used plain, non-Camel-prefixed values. Because these names do not start with the Camel / camel prefix, HttpHeaderFilterStrategy - which blocks only the Camel header namespace on the HTTP boundary - let them pass from an inbound HTTP request straight into the Exchange. In a route that bridges an HTTP consumer (for example platform-http) into a salesforce: producer, any HTTP client could therefore set these headers and override what the route intended - supplying its own SOQL query or SOSL search to read data from any SObject the connected Salesforce user can access, overriding the target SObject name and id for CRUD operations, or redirecting an Apex REST call to a different endpoint and HTTP method (including destructive methods) with injected query parameters. All such operations run with the full permissions of the Salesforce connected (integration) user, which is typically broad. No credentials are required from the attacker when the bridging consumer is unauthenticated. This issue affects Apache Camel: from 4.0.0 before 4.14.8, from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0. Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.8. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. After upgrading, routes that set Salesforce operation parameters via the raw header names must use the CamelSalesforce* names (for example CamelSalesforceSObjectQuery and CamelSalesforceApexUrl) instead of the old sObject* / apex* values; the endpoint-option spelling is unchanged. For deployments that cannot upgrade immediately, strip the Salesforce control headers from any untrusted ingress before the salesforce: producer (for example removeHeaders('sObject*') and removeHeaders('apex*') at the start of the route), and set the query, SObject and Apex parameters from a trusted source.

Assessing the Risk of CVE-2026-49099

Access Complexity Graph

The exploitability of CVE-2026-49099 depends on two key factors: attack complexity (the level of effort required to execute an exploit) and privileges required (the access level an attacker needs).

Exploitability Analysis for CVE-2026-49099

With low attack complexity and no required privileges, CVE-2026-49099 is an easy target for cybercriminals. Organizations should prioritize immediate mitigation measures to prevent unauthorized access and data breaches.

Understanding AC and PR

A lower complexity and fewer privilege requirements make exploitation easier. Security teams should evaluate these aspects to determine the urgency of mitigation strategies, such as patch management and access control policies.

Attack Complexity (AC) measures the difficulty in executing an exploit. A high AC means that specific conditions must be met, making an attack more challenging, while a low AC means the vulnerability can be exploited with minimal effort.

Privileges Required (PR) determine the level of system access necessary for an attack. Vulnerabilities requiring no privileges are more accessible to attackers, whereas high privilege requirements limit exploitation to authorized users with elevated access.

CVSS Score Breakdown Chart

Above is the CVSS Sub-score Breakdown for CVE-2026-49099, illustrating how Base, Impact, and Exploitability factors combine to form the overall severity rating. A higher sub-score typically indicates a more severe or easier-to-exploit vulnerability.

CIA Impact Analysis

Below is the Impact Analysis for CVE-2026-49099, showing how Confidentiality, Integrity, and Availability might be affected if the vulnerability is exploited. Higher values usually signal greater potential damage.

  • Confidentiality: Low
    CVE-2026-49099 could lead to minor leaks of non-critical information without major privacy breaches.
  • Integrity: None
    CVE-2026-49099 poses no threat to data integrity.
  • Availability: None
    CVE-2026-49099 does not impact system availability.

CVE-2026-49099 References

External References

CWE Common Weakness Enumeration

CWE-639

Vulnerable Configurations

  • cpe:2.3:a:apache:camel:4.0.0:-:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:-:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:rc1:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:rc1:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:rc2:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:rc2:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:milestone1:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:milestone1:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:milestone2:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:milestone2:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:milestone3:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:milestone3:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.6:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.6:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.2.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.2.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.3.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.6.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.7.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.7.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.6:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.6:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.7:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.7:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.8:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.8:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.9:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.9:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.9.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.9.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.6:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.6:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.7:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.7:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.8:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.8:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.9:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.9:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.11.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.11.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.12.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.12.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.13.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.13.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.6:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.6:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.7:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.7:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.15.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.15.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.16.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.16.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.17.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.17.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.17.0.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.17.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.18.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.18.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.18.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.18.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.18.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.18.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.19.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.19.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.20.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.20.0:*:*:*:*:*:*:*

Protect Your Infrastructure against CVE-2026-49099: Combat Critical CVE Threats

Stay updated with real-time CVE vulnerabilities and take action to secure your systems. Enhance your cybersecurity posture with the latest threat intelligence and mitigation techniques. Develop the skills necessary to defend against CVEs and secure critical infrastructures. Join the top cybersecurity professionals safeguarding today's infrastructures.

Other 5 Recently Published CVEs Vulnerabilities

  • CVE-2026-89172 – Improper protection of physical side channels vulnerability in Microchip AN1044, Microchip AN953, and Microchip SW300052. This issue affects AN104...
  • CVE-2026-85200 – The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.5.5.3 via the gmw_posts_locator_aj...
  • CVE-2026-85198 – The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable to generic SQL Injection via URL Path i...
  • CVE-2026-78175 – The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and includin...
  • CVE-2026-78159 – The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_arra...