THREATOPS
THREAT OPSThreat News › CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted

CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted

medoss_secPublished 2026-08-24

<p>Posted by Andrea Cosentino on Aug 24</p>Severity: important <br /> <br /> Affected versions:<br /> <br /> - Apache Camel (org.apache.camel:camel-platform-http-main) 4.8.0 before 4.22.0<br /> <br /> Description:<br /> <br /> Improper Authentication vulnerability in Apache Camel Platform HTTP Main component.<br /> <br /> This issue affects Apache Camel: from 4.8.0 before 4.22.0.<br /> <br /> The

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/566