CVE-2026-66906

Apache Camel
25/100
exploitation likelihood
CVSS9.1
EPSS0.4%
KEVNone
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download an Azure Storage blob to the local filesystem through its downloadBlobToFile operation, writing into the directory named by the fileDir endpoint option, which is documented as usable from both the producer and the consumer. BlobOperations.downlo
EPSS 0.004 (probability of exploitation) · CVSS base 9.1 · 1 public PoC/exploit reference(s) available
Public PoC / Exploit1

Defensive review only — these references demonstrate exploitability.

References2