CVE-2026-96740
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Workarounds
Restrict create, update, and patch permissions for Console custom resources to trusted administrators only. Where supported, apply a NetworkPolicy to restrict Console API egress to approved Kafka broker endpoints. These controls reduce exposure to the reported ServiceAccount-credential disclosure path but do not replace the permanent fix, which is to filter security-sensitive Kafka client properties. Upgrade to a release containing the permanent fix when available.
References
- https://access.redhat.com/security/cve/CVE-2026-96740
- https://bugzilla.redhat.com/show_bug.cgi?id=2539427
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.