CVE-2026-66907 Vulnerability Analysis & Exploit Details

CVE-2026-66907
Vulnerability Scoring

7.5
/10
Very High Risk

Highly exploitable, CVE-2026-66907 poses a critical security risk that could lead to severe breaches.

Attack Complexity Details

  • Attack Complexity: Low
    Exploits can be performed without significant complexity or special conditions.
  • Attack Vector: Network
    Vulnerability is exploitable over a network without physical access.
  • Privileges Required: None
    No privileges are required for exploitation.
  • Scope: Unchanged
    Exploit remains within the originally vulnerable component.
  • User Interaction: None
    No user interaction is necessary for exploitation.

CVE-2026-66907 Details

Status: Analyzed

Last updated: 🕣 27 Aug 2026, 20:35 UTC
Originally published on: 🕔 24 Aug 2026, 17:18 UTC

Time between publication and last update: 3 days

CVSS Release: version 3

CVSS3 Source

134c704f-9b21-4f2e-91b3-4a467353bcc0

CVSS3 Type

Secondary

CVSS3 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2026-66907 Vulnerability Summary

CVE-2026-66907: Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google Cloud Storage objects to the local filesystem when the downloadFileName option is set. That option is documented as a folder or a filename, and when its value contains no expression token the consumer builds the local destination by appending the object name to it: evaluateFileExpression sets the Exchange file-name header to the remote object name and evaluates downloadFileName + "/${file:name}". The ${file:name} token returns the file-name header verbatim, unlike ${file:onlyname}, which applies FileUtil.stripPath to it. The resulting string was passed directly to new File(result) and blob.downloadTo(file.toPath()) with no lexical normalization and no check that the destination stayed inside the configured directory. The object name is not route-controlled data: the consumer lists the bucket, iterates every returned blob and creates one exchange per object from blob.getBlobId().getName() verbatim, and the filter option that could restrict those names is not applied at all unless it has been explicitly set. Google Cloud Storage object names are opaque UTF-8 keys that the service stores and lists exactly as written, with no server-side canonicalization, and a forward slash is only a display convention for pseudo-directories, so a key containing parent-directory segments survives round-tripping intact. An object name containing such segments therefore resolved to a location outside the configured downloadFileName directory, letting anyone able to influence the names present in the consumed bucket cause Camel to create or overwrite a file at a location of their choosing, with the privileges of the Camel process. Depending on what the process can write to, overwriting a file outside the download directory can escalate beyond the loss of integrity of that file. The downloadFileName option is an ordinary consumer parameter and carries no security marker, so nothing signalled to users that its value was not being enforced as a containment boundary. The defect is consumer-only; the producer has no download-to-file sink. Camel's other file-download consumers - camel-file, camel-ftp, camel-smb, camel-mina-sftp, camel-azure-files and the Azure Storage download paths - already constrained their local downloads to the configured directory using a path-segment boundary check; camel-google-storage was the remaining object-store download sink not covered by that work. Users are recommended to upgrade to version 4.22.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.9. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.4. For deployments that cannot upgrade immediately, set the filter option to a regular expression that accepts only simple single-segment object names, so that any name carrying a path separator or a parent-directory segment is excluded before an exchange is created; note that no filtering whatsoever is applied when the option is left unset, and that the expression is matched against the whole object name. Alternatively, give downloadFileName an explicit expression that does not carry the remote path through, for example one built on ${file:onlyname} rather than the implicit ${file:name}, keeping in mind that a downloadFileName containing an expression is treated as route-author-controlled and is not covered by the containment check added in the fix. As defence in depth, treat the object names in any externally writable bucket as untrusted input and do not derive local filesystem paths from them.

Assessing the Risk of CVE-2026-66907

Access Complexity Graph

The exploitability of CVE-2026-66907 depends on two key factors: attack complexity (the level of effort required to execute an exploit) and privileges required (the access level an attacker needs).

Exploitability Analysis for CVE-2026-66907

With low attack complexity and no required privileges, CVE-2026-66907 is an easy target for cybercriminals. Organizations should prioritize immediate mitigation measures to prevent unauthorized access and data breaches.

Understanding AC and PR

A lower complexity and fewer privilege requirements make exploitation easier. Security teams should evaluate these aspects to determine the urgency of mitigation strategies, such as patch management and access control policies.

Attack Complexity (AC) measures the difficulty in executing an exploit. A high AC means that specific conditions must be met, making an attack more challenging, while a low AC means the vulnerability can be exploited with minimal effort.

Privileges Required (PR) determine the level of system access necessary for an attack. Vulnerabilities requiring no privileges are more accessible to attackers, whereas high privilege requirements limit exploitation to authorized users with elevated access.

CVSS Score Breakdown Chart

Above is the CVSS Sub-score Breakdown for CVE-2026-66907, illustrating how Base, Impact, and Exploitability factors combine to form the overall severity rating. A higher sub-score typically indicates a more severe or easier-to-exploit vulnerability.

CIA Impact Analysis

Below is the Impact Analysis for CVE-2026-66907, showing how Confidentiality, Integrity, and Availability might be affected if the vulnerability is exploited. Higher values usually signal greater potential damage.

  • Confidentiality: High
    Exploiting CVE-2026-66907 can result in unauthorized access to sensitive data, severely compromising data privacy.
  • Integrity: None
    CVE-2026-66907 poses no threat to data integrity.
  • Availability: None
    CVE-2026-66907 does not impact system availability.

CVE-2026-66907 References

External References

CWE Common Weakness Enumeration

CWE-23

CAPEC Common Attack Pattern Enumeration and Classification

  • Relative Path Traversal CAPEC-139 An attacker exploits a weakness in input validation on the target by supplying a specially constructed path utilizing dot and slash characters for the purpose of obtaining access to arbitrary files or resources. An attacker modifies a known path on the target in order to reach material that is not available through intended channels. These attacks normally involve adding additional path separators (/ or \) and/or dots (.), or encodings thereof, in various combinations in order to reach parent directories or entirely separate trees of the target's directory structure.
  • Manipulating Web Input to File System Calls CAPEC-76 An attacker manipulates inputs to the target software which the target software passes to file system calls in the OS. The goal is to gain access to, and perhaps modify, areas of the file system that the target software did not intend to be accessible.

Vulnerable Configurations

  • cpe:2.3:a:apache:camel:4.0.0:-:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:-:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:rc1:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:rc1:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:rc2:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:rc2:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:milestone1:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:milestone1:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:milestone2:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:milestone2:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.0:milestone3:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.0:milestone3:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.0.6:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.0.6:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.1.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.2.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.2.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.3.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.4.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.4.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.5.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.6.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.7.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.7.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.6:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.6:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.7:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.7:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.8:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.8:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.8.9:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.8.9:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.9.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.9.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.6:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.6:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.7:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.7:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.8:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.8:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.10.9:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.10.9:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.11.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.11.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.12.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.12.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.13.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.13.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.4:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.4:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.5:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.5:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.6:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.6:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.7:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.7:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.14.8:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.14.8:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.15.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.15.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.16.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.16.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.17.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.17.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.17.0.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.17.0.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.18.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.18.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.18.1:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.18.1:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.18.2:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.18.2:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.18.3:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.18.3:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.19.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.19.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.20.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.20.0:*:*:*:*:*:*:*
  • cpe:2.3:a:apache:camel:4.21.0:*:*:*:*:*:*:*
    cpe:2.3:a:apache:camel:4.21.0:*:*:*:*:*:*:*

Protect Your Infrastructure against CVE-2026-66907: Combat Critical CVE Threats

Stay updated with real-time CVE vulnerabilities and take action to secure your systems. Enhance your cybersecurity posture with the latest threat intelligence and mitigation techniques. Develop the skills necessary to defend against CVEs and secure critical infrastructures. Join the top cybersecurity professionals safeguarding today's infrastructures.

Other 5 Recently Published CVEs Vulnerabilities

  • CVE-2026-97318 – The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not properly validate a giveaway's parent page URL before saving it...
  • CVE-2026-97317 – The Giveaways and Contests by RafflePress WordPress plugin before 1.12.27 does not remove the reCAPTCHA secret key from the giveaway settings it e...
  • CVE-2026-94298 – The BuildKit WordPress plugin before 1.0.29 does not properly sanitise and escape data submitted by contributor-level users before storing it and ...
  • CVE-2026-92820 – The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the...
  • CVE-2026-92174 – The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.73.2 via the 'them...