S4E just found a high top 10 tcp port service scan
critical·Product Based Network Vulnerabilities·Updated May 21, 2026

CVE-2026-33453 Scanner

CVE-2026-33453 Scanner - Remote Code Execution (RCE) vulnerability in Apache Camel

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-33453
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Apache Camel Camel-Coap component. Apache Camel's camel-coap component is vulnerable to Camel message header injection, leading to remote code execution when routes forward CoAP requests to header-sensitive producers (e.g. camel-exec) The camel-coap component maps incoming CoAP request URI query parameters directly into Camel Exchange In message headers without applying any HeaderFilterStrategy.   Specifically, CamelCoapResource.handleRequest() iterates over OptionSet.getUriQuery() and calls camelExchange.getIn().setHeader(...) for every query parameter. CoAPEndpoint extends DefaultEndpoint rather than DefaultHeaderFilterStrategyEndpoint, and CoAPComponent does not implement HeaderFilterStrategyComponent; the component contains no references to HeaderFilterStrategy at all. As a result, an unauthenticated attacker who can send a single CoAP UDP packet to a Camel route consuming from coap:// can inject arbitrary Camel internal headers (those prefixed with Camel*) into the Exchange. When the route delivers the message to a header-sensitive producer such as camel-exec, camel-sql, camel-bean, camel-file, or template components (camel-freemarker, camel-velocity), the injected headers can alter the producer's behavior. In the case of camel-exec, the CamelExecCommandExecutable and CamelExecCommandArgs headers override the executable and arguments configured on the endpoint, resulting in arbitrary OS command execution under the privileges of the Camel process. The producer's output is written back to the Exchange body and returned in the CoAP response payload by CamelCoapResource, giving the attacker an interactive RCE channel without any need for out-of-band exfiltration.                                                                                                                                                                         Exploitation prerequisites are minimal: a single unauthenticated UDP datagram to the CoAP port (default 5683). CoAP (RFC 7252) has no built-in authentication, and DTLS is optional and disabled by default. Because the protocol is UDP-based, HTTP-layer WAF/IDS controls do not apply. This issue affects Apache Camel: from 4.14.0 through 4.14.5, from 4.18.0 before 4.18.1, 4.19.0. Users are recommended to upgrade to version 4.18.1 or 4.19.0, fixing the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Camelby Apache Software Foundation
4.14.0
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14by Red Hat
Red Hat Fuse 7by Red Hat
Red Hat Fuse 7by Red Hat
Updated Aug 19, 2026View on NVD →
Detail

Apache Camel is an open-source integration framework that provides connectivity to a wide variety of protocols and APIs. It is widely adopted by developers and enterprises for building integration solutions. The framework supports a wide range of transport and messaging models and allows seamless interaction with both source and destination application systems. Specifically, the camel-coap component facilitates communication via the CoAP protocol, which is a specialized web transfer protocol widely applied in constrained environments, such as Internet of Things (IoT) applications. Users across numerous industries manage their APIs and services through Apache Camel, leveraging its integrations and reliability. The vulnerability, therefore, has broad implications for a multitude of businesses relying on this framework.

The Remote Code Execution (RCE) vulnerability in Apache Camel, identified as CVE-2026-33453, arises from improper filtering of header fields in CoAP URI query parameters. This flaw permits unauthenticated attackers to inject CoAP headers and execute arbitrary OS commands through header-sensitive producers. Such vulnerabilities in widely-used frameworks like Apache Camel can significantly compromise system integrity if exploited. Administrators and developers are urged to address these threats to prevent unauthorized access and potential data breaches. The CVSS score highlights the critical nature and potential impact of this vulnerability. Ensuring systems are patched against this RCE threat is crucial.

This vulnerability occurs at the intersection of web protocols and command execution, facilitated by improperly sanitized input in the camel-coap component. Critical components such as the CoAP URI query parameters fail to filter headers adequately. As a technical detail, succeeding in such exploits involves malicious CoAP UDP packets, which are improperly processed by some versions of Camel. Furthermore, the ability of an attacker to execute arbitrary commands is concerning due to the high damage potential in multi-user environments. Timely application of security patches can prevent such exploitation.

Should this vulnerability be exploited by threat actors, the impacts could be severe, with potential full system compromise under the privileges of the Camel process. The repercussions may include unauthorized data access, system manipulation, and service disruption. Organizations could suffer data breaches, service outages, and reputational damage. The exploitation of such a vulnerability could allow attackers to serve their malicious intents with broad access to constrained environments like IoT devices, causing significant harm or security policy violations. Effective preventative measures are necessary to protect against these significant risks.

REFERENCES

Solution Advice
  • Upgrade to Apache Camel version 4.18.1, 4.19.0, or later to mitigate this vulnerability.
  • Implement input validation and filtering to prevent unauthorized header injections.
  • Regularly update and patch all software components to ensure protection against known vulnerabilities.
  • Monitor system logs and network traffic for unusual activities or unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.