CVE-2026-53913

CRITICALPre-NVD 9.89.8
EchelonGraph scoreHIGH confidence

Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2026-07-06. CISA-ADP (Vulnrichment) CVSS v3.1 baseline 9.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: cisa-adp, epss, ghsa
9.8
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS: 1%CVSS: 9.8Exploit: NoneExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.

The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three checks in sequence: it rejects a request that carries no access token, then - only if requiredRoles is non-empty - validates the roles, and - only if requiredPermissions is non-empty - validates the permissions. The actual cryptographic verification of the bearer access token (signature, issuer and expiry for a local JWT, or active-state and issuer for token introspection) is performed exclusively inside those role and permission checks. KeycloakSecurityPolicy defaults requiredRoles and requiredPermissions to empty - which is the documented 'Basic Setup' - so on a route configured that way the role and permission checks are skipped and the access token is therefore never verified. The token-presence check still rejects a missing token, but an invalid token is accepted: any non-null value in the Authorization: Bearer header - including an arbitrary string or a forged, unsigned JWT - passes the policy and the request reaches the protected route, with no signature, issuer or expiry check and no request to Keycloak. The token is read from the inbound request header because allowTokenFromHeader defaults to true. Because the normal reason to place a route behind this policy is that the route performs server-side work, the bypass results in unauthenticated access to that work; where the protected route forwards to a code-execution-capable producer, it can result in unauthenticated remote code execution. This defect is independent of CVE-2026-23552: that issue concerned the issuer claim and was fixed by adding a check inside the verification routine, but here the verification routine is not reached at all in the default configuration, so the defect remains. This issue affects Apache Camel: from 4.15.0 before 4.18.3, from 4.19.0 before 4.21.0.

Users are recommended to upgrade to version 4.21.0, which fixes the issue. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.3. For deployments that cannot upgrade immediately, configure a non-empty requiredRoles or requiredPermissions on every KeycloakSecurityPolicy so that the token-verification path is exercised, set allowTokenFromHeader to false where the token is not expected from the request header, or perform token verification at the framework layer ahead of the policy.

CVSS v3
9.8
EG Score
9.8(high)
EG Risk
EPSS
46.0%
KEV
Not listed

Published

July 6, 2026

Last Modified

July 9, 2026

Advisory Details (1)

Auto-updated Jul 18, 2026
No patch confirmed yet.
generic

Apache Camel Security Advisory - CVE-2026-53913 - Apache Camel

https://camel.apache.org/security/CVE-2026-53913.html

Vendor Advisories for CVE-2026-53913(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Weakness Classification(3)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Data Freshness Timeline

(refreshed 17× in last 7d / 85× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-07-22 14:08 UTCEPSS rescore
  2. 2026-07-21 15:25 UTCEPSS rescore
  3. 2026-07-20 17:08 UTCEPSS rescore
  4. 2026-07-19 14:31 UTCEPSS rescore
  5. 2026-07-19 14:31 UTCEPSS rescore
  6. 2026-07-19 02:29 UTCEPSS rescore
  7. 2026-07-18 10:04 UTCEPSS rescore
  8. 2026-07-17 06:32 UTCGHSA enrichment
  9. 2026-07-17 02:52 UTCGHSA enrichment
  10. 2026-07-16 23:13 UTCGHSA enrichment
  11. 2026-07-16 19:34 UTCGHSA enrichment
  12. 2026-07-16 17:03 UTCEPSS rescore
  13. 2026-07-16 15:44 UTCGHSA enrichment
  14. 2026-07-16 12:05 UTCGHSA enrichment
  15. 2026-07-16 08:26 UTCGHSA enrichment
  16. 2026-07-16 04:47 UTCGHSA enrichment
  17. 2026-07-16 01:08 UTCGHSA enrichment
  18. 2026-07-15 21:29 UTCGHSA enrichment
  19. 2026-07-15 17:50 UTCGHSA enrichment
  20. 2026-07-15 16:57 UTCEPSS rescore
  21. 2026-07-15 16:57 UTCEPSS rescore
  22. 2026-07-15 14:05 UTCGHSA enrichment
  23. 2026-07-15 10:27 UTCGHSA enrichment
  24. 2026-07-15 06:48 UTCGHSA enrichment
  25. 2026-07-15 03:09 UTCGHSA enrichment
Show 60 more
  1. 2026-07-15 02:00 UTCEPSS rescore
  2. 2026-07-15 02:00 UTCEPSS rescore
  3. 2026-07-14 23:29 UTCGHSA enrichment
  4. 2026-07-14 19:50 UTCGHSA enrichment
  5. 2026-07-14 16:12 UTCGHSA enrichment
  6. 2026-07-14 12:31 UTCGHSA enrichment
  7. 2026-07-14 08:52 UTCGHSA enrichment
  8. 2026-07-14 05:12 UTCGHSA enrichment
  9. 2026-07-14 01:33 UTCGHSA enrichment
  10. 2026-07-13 22:31 UTCEPSS rescore
  11. 2026-07-13 21:55 UTCGHSA enrichment
  12. 2026-07-13 18:17 UTCGHSA enrichment
  13. 2026-07-13 14:36 UTCGHSA enrichment
  14. 2026-07-13 10:57 UTCGHSA enrichment
  15. 2026-07-13 07:18 UTCGHSA enrichment
  16. 2026-07-13 06:13 UTCEPSS rescore
  17. 2026-07-13 06:13 UTCEPSS rescore
  18. 2026-07-13 03:38 UTCGHSA enrichment
  19. 2026-07-12 23:59 UTCGHSA enrichment
  20. 2026-07-12 20:21 UTCGHSA enrichment
  21. 2026-07-12 16:42 UTCGHSA enrichment
  22. 2026-07-12 13:04 UTCGHSA enrichment
  23. 2026-07-12 09:24 UTCGHSA enrichment
  24. 2026-07-12 05:46 UTCEPSS rescore
  25. 2026-07-12 05:45 UTCGHSA enrichment
  26. 2026-07-12 02:07 UTCGHSA enrichment
  27. 2026-07-11 22:28 UTCGHSA enrichment
  28. 2026-07-11 18:49 UTCGHSA enrichment
  29. 2026-07-11 15:11 UTCGHSA enrichment
  30. 2026-07-11 11:29 UTCGHSA enrichment
  31. 2026-07-11 08:27 UTCEPSS rescore
  32. 2026-07-11 08:27 UTCEPSS rescore
  33. 2026-07-11 07:51 UTCGHSA enrichment
  34. 2026-07-11 04:12 UTCGHSA enrichment
  35. 2026-07-11 00:32 UTCGHSA enrichment
  36. 2026-07-10 20:53 UTCGHSA enrichment
  37. 2026-07-10 17:14 UTCGHSA enrichment
  38. 2026-07-10 13:35 UTCGHSA enrichment
  39. 2026-07-10 09:55 UTCGHSA enrichment
  40. 2026-07-10 06:16 UTCGHSA enrichment
  41. 2026-07-10 02:37 UTCGHSA enrichment
  42. 2026-07-09 22:57 UTCGHSA enrichment
  43. 2026-07-09 19:19 UTCGHSA enrichment
  44. 2026-07-09 19:10 UTCEPSS rescore
  45. 2026-07-09 19:10 UTCEPSS rescore
  46. 2026-07-09 15:40 UTCGHSA enrichment
  47. 2026-07-09 11:58 UTCGHSA enrichment
  48. 2026-07-09 08:19 UTCGHSA enrichment
  49. 2026-07-09 04:41 UTCEG score recompute 9.80
  50. 2026-07-09 04:41 UTCGHSA enrichment
  51. 2026-07-08 15:16 UTCEPSS rescore
  52. 2026-07-08 15:16 UTCEPSS rescore
  53. 2026-07-07 13:46 UTCEPSS rescore
  54. 2026-07-07 13:46 UTCEPSS rescore
  55. 2026-07-07 13:06 UTCMITRE cvelistV5CVSS v3 → 9.8 · severity → CRITICAL
  56. 2026-07-06 16:27 UTCEPSS rescore
  57. 2026-07-06 16:27 UTCEPSS rescore
  58. 2026-07-06 09:42 UTCNVD update
  59. 2026-07-06 08:52 UTCEG score recompute
  60. 2026-07-06 08:51 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-53913?
CVE-2026-53913 is a critical vulnerability published on July 6, 2026. Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component. The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which performs three…
When was CVE-2026-53913 disclosed?
CVE-2026-53913 was first published in the National Vulnerability Database on July 6, 2026, with the most recent update on July 9, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-53913 actively exploited?
CVE-2026-53913 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 46.0% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
What is the CVSS score of CVE-2026-53913?
CVE-2026-53913 has a CVSS v3.1 base score of 9.8 (CISA-ADP / Vulnrichment enrichment; NVD's own analysis pending).
How do I remediate CVE-2026-53913?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-53913, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-53913

Explore →

Is Your Infrastructure Affected by CVE-2026-53913?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.