CVE-2026-96740

Summary

A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

Workarounds

Restrict create, update, and patch permissions for Console custom resources to trusted administrators only. Where supported, apply a NetworkPolicy to restrict Console API egress to approved Kafka broker endpoints. These controls reduce exposure to the reported ServiceAccount-credential disclosure path but do not replace the permanent fix, which is to filter security-sensitive Kafka client properties. Upgrade to a release containing the permanent fix when available.

References