Skip to content
CVE-2026-88789: High-Risk XML Vulnerability in Apache Camel Quarkus

CVE-2026-88789: High-Risk XML Vulnerability in Apache Camel Quarkus

First seen 2 Oct 2026, 08:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 09:07 UTC
  • •CVE-2026-88789 affects Apache Camel Quarkus versions 3.2.0 to 3.40.0.
  • •The vulnerability allows attackers to read local files and access internal networks.
  • •A proof-of-concept was published on 2026-10-01, but no active exploitation has been confirmed.

CVE-2026-88789 is a vulnerability in the XSLT support extension of Apache Camel Quarkus, affecting versions from 3.2.0 to 3.40.0. This flaw allows attackers to read local files or access internal network locations by supplying a malicious XML document with external entity declarations. The vulnerability arises from the extension's use of an insecure Xalan-backed TransformerFactory that does not enforce external access restrictions. A proof-of-concept (PoC) for this vulnerability was published on 2026-10-01. The CVSS score for this vulnerability is 8.6, indicating high severity. As of now, active exploitation has not been confirmed, but the potential for exploitation is significant. Users are advised to upgrade to versions 3.33.3 or 3.40.0 or later to mitigate this risk.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-01-29
CVE-2026-1340 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-01
CVE-2026-88789 published
Apache Camel Quarkus vulnerability disclosed, allowing XML external entity attacks.
Sploitus
2026-10-02
CVE-2026-88789 reported on Ismalicious
Ismalicious reported on the vulnerability's details, including its CVSS score of 8.6.
Ismalicious

More articles in this cluster (2)

Following this threat?

Track CVE-2026-1340 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Apache Camel Quarkus are affected?
The vulnerability affects versions from 3.2.0 before 3.33.3 and from 3.34.0 before 3.40.0.
Is there any active exploitation of this vulnerability?
As of now, active exploitation of CVE-2026-88789 has not been confirmed.
What should users do to protect themselves?
Users should upgrade to Apache Camel Quarkus version 3.33.3 or later to mitigate the risk.