Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code execution within the operator pod, potentially enabling tenants to execute arbitrary code with the privileges of the operator. This issue affects Apache Camel K: from 2.0.0 before 2.9.3, from 2.10.1 before 2.10.2. Users are recommended to upgrade to version 2.9.3, 2.10.2 or 2.11.0, which fixes the issue.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Apache Camel K versions 2.0.0 through 2.9.2 and 2.10.1 contain a critical eval injection vulnerability (CVE-2026-80351, CVSS 9.8) in how Maven configurations are dynamically evaluated. The flaw allows tenant-controlled repository content to inject arbitrary directives into code execution contexts, granting attackers the ability to execute code with operator pod privileges. This is particularly dangerous in multi-tenant Kubernetes environments where Camel K operators manage integrations across isolated namespaces. Any organization deploying affected versions faces immediate risk of lateral movement, data exfiltration, and complete cluster compromise, as the operator's elevated permissions become a pivot point for enterprise-wide attacks.
While MITRE ATT&CK techniques are not formally mapped to this CVE, the exploitation pattern aligns with code injection and execution methods. Casky.ai's platform, though currently showing zero matching skills for this specific vulnerability, would typically detect such attacks by analyzing unsafe code evaluation patterns, untrusted input flows into dynamic execution contexts, and privilege escalation chains. A practitioner using Casky would investigate findings around CWE-95 violations by tracing Maven dependency resolution processes, examining operator pod logs for unexpected code instantiation, and identifying where tenant-supplied repository URLs bypass input validation. Security teams should immediately audit their Camel K deployments, apply patches to versions 2.9.3 or 2.10.2+, and implement network policies restricting operator access to only trusted Maven repositories.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-80351. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation