Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-66906 — Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-66906) in camel-azure-storage-blob, demonstrating arbitrary file write via blob name traversal, with affected and fixed version details. | Kitploit
Tools/GitHubGitHub/oscerd/cve-2026-66906
Vulnerability AnalysisExploitationWeb Application ExploitationPapers & ResearchLearning & Education
GitHuboscerd/cve-2026-66906

CVE-2026-66906

Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-66906) in camel-azure-storage-blob, demonstrating arbitrary file write via blob name traversal, with affected and fixed version details.

View Repository
9h 37m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-66906 — camel-azure-storage-blob downloadBlobToFile path traversal

Runnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:

Both are affected versions (the issue is fixed in 4.14.9 / 4.18.4 / 4.22.0), and both demonstrate the identical defect: the camel-azure-storage-blob consumer downloads container blobs to the local filesystem into the directory named by the fileDir option, building the local target as new File(fileDir, client.getBlobName()) — the remote blob name exactly as the Azure SDK reported it, with no normalization and no check that the resolved location stays inside fileDir. The blob name is not route-controlled: the consumer lists the container (BlobConsumer.createBatchExchangesFromContainer) and downloads every blob. A blob whose name contains ../ segments is therefore written outside fileDir (CWE-22, path traversal → arbitrary file write).

Each subdirectory is self-contained (its own Dockerfile, docker-compose.yml bringing up an Azurite emulator, and README). In short, for either:

root@kitploit:~
cd camel-spring-boot   # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down

Expected output on an affected build (both variants):

root@kitploit:~
Files inside the intended download directory /app/downloads:
    - report.txt
File written OUTSIDE it, at /tmp/pwned-66906.txt: true
    content: PWNED via path traversal — CVE-2026-66906
>>> PROVEN: the blob name's ../ segments escaped the configured fileDir directory ... : true

Vulnerability Summary

Advisory: https://camel.apache.org/security/CVE-2026-66906.html

The fix

The consumer now resolves and constrains the download target to the configured fileDir directory (via AzureFileNameHelper.resolveWithinDirectory), rejecting blob names that would escape it. The same fix covers the sibling components camel-azure-storage-datalake (CVE-2026-60093).

Disclaimer

This repository is published for educational and defensive purposes: to help Apache Camel users understand the vulnerability, verify whether they are affected, and confirm that upgrading resolves it. The written file is a benign marker under /tmp. Do not use this material against systems you do not own or operate.

Download Tool
RuntimeDirectoryStack
Camel Spring Bootcamel-spring-boot/Spring Boot 3.5.13 + camel-azure-storage-blob 4.18.2
Camel Quarkuscamel-quarkus/Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel 4.20.0)
PropertyValue
Componentcamel-azure-storage-blob (Spring Boot: camel-azure-storage-blob-starter; Quarkus: camel-quarkus-azure-storage-blob)
CWECWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal)
Attack vectorA container blob whose name contains ../ segments, downloaded by the consumer with fileDir set
ImpactArbitrary file write outside the configured fileDir directory
Affected VersionsFrom 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0
Fixed Versions4.14.9, 4.18.4, 4.22.0
JIRACAMEL-23942
Creditn0mi1k; Hiep Nguyen