Sploitus

Exploit for CVE-2026-60093

githubexploit Β· 2026-08-24

Exploit Code

README72 lines
## https://sploitus.com/exploit?id=6694239F-3F74-59CD-A5FA-51EF6A6B2D27
# CVE-2026-60093 β€” camel-azure-storage-datalake `downloadToFile` path traversal

Runnable proof-of-concept reproducers for the same Apache Camel vulnerability, one per runtime:

| Runtime | Directory | Stack |
|---------|-----------|-------|
| **Camel Spring Boot** | [`camel-spring-boot/`](camel-spring-boot/) | Spring Boot 3.5.13 + camel-azure-storage-datalake **4.18.2** |
| **Camel Quarkus** | [`camel-quarkus/`](camel-quarkus/) | Quarkus 3.36.0 + Camel Quarkus 3.36.0 (bundles Camel **4.20.0**) |

Both are **affected** versions (the issue is fixed in 4.14.9 / 4.18.4 / 4.22.0), and both demonstrate the identical
defect: the camel-azure-storage-datalake component can download an ADLS Gen2 file to the local filesystem through
its `downloadToFile` operation, writing into the directory named by the `fileDir` option.
`DataLakeFileOperations.downloadToFile` built the local target by joining `fileDir` with the remote path name
exactly as the Azure SDK reported it (`new File(fileDir, fileClientWrapper.getFileName())`) β€” with **no** lexical
normalization and **no** check that the resolved location stayed inside `fileDir`. The remote name is not
route-controlled: the consumer enumerates the filesystem (`DataLakeConsumer.createBatchExchangesFromPath`) and
downloads every entry. A path name containing `../` segments therefore resolves **outside** `fileDir` (CWE-22, path
traversal β†’ arbitrary file write).

> **Note on the test harness.** The Azure **Data Lake Gen2** API is not implemented by any available local emulator
> β€” Azurite returns HTTP 400 for Gen2 `listPaths` and file operations. These reproducers therefore drive the exact
> vulnerable code (`DataLakeFileOperations.downloadToFile` β†’ `new File(fileDir, fileClientWrapper.getFileName())`)
> **directly**, supplying a Data Lake file client wrapper whose `getFileName()` returns the remote name β€” exactly
> as the consumer supplies the name it read from `PathItem.getName()`. The sibling component
> `camel-azure-storage-blob` shares the same fix ([CVE-2026-66906](https://camel.apache.org/security/CVE-2026-66906.html))
> and there the identical defect is reproduced end-to-end against a live Azurite emulator.

```bash
cd camel-spring-boot   # or: cd camel-quarkus
mvn clean package
docker compose up -d --build
curl -s http://localhost:8080/exploit/attack
docker compose down
```

Expected output on an affected build (both variants):

```
2) Download of a file named '../../../../../../tmp/pwned-60093.txt':
     resolved local target: /app/downloads/../../../../../../tmp/pwned-60093.txt
File written OUTSIDE it, at /tmp/pwned-60093.txt: true
    content: PWNED via path traversal β€” CVE-2026-60093
>>> PROVEN: DataLakeFileOperations.downloadToFile built the local target as new File(fileDir, fileName) ... : true
```

## Vulnerability Summary

| Property | Value |
|----------|-------|
| **Component** | `camel-azure-storage-datalake` (Spring Boot: `camel-azure-storage-datalake-starter`; Quarkus: `camel-quarkus-azure-storage-datalake`) |
| **CWE** | CWE-22 (Improper Limitation of a Pathname to a Restricted Directory β€” Path Traversal) |
| **Attack vector** | A Gen2 file whose path name contains `../` segments, downloaded by the consumer with `fileDir` set |
| **Impact** | Arbitrary file write outside the configured `fileDir` directory |
| **Affected Versions** | From 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0 |
| **Fixed Versions** | 4.14.9, 4.18.4, 4.22.0 |
| **JIRA** | [CAMEL-23942](https://issues.apache.org/jira/browse/CAMEL-23942) |
| **Credit** | n0mi1k; Hiep Nguyen |

Advisory: https://camel.apache.org/security/CVE-2026-60093.html

## The fix

The consumer now resolves and constrains the download target to the configured `fileDir` directory (via
`AzureFileNameHelper.resolveWithinDirectory`), rejecting path names that would escape it β€” the same fix that covers
`camel-azure-storage-blob` ([CVE-2026-66906](https://camel.apache.org/security/CVE-2026-66906.html)).

## Disclaimer

This repository is published for educational and defensive purposes: to help Apache Camel users understand the
vulnerability, verify whether they are affected, and confirm that upgrading resolves it. The written file is a
benign marker under `/tmp`. Do not use this material against systems you do not own or operate.