Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96740— Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka client properties → sa-token exfiltration via config.providers

Quick assessment

Affected
Red Hat streams for Apache Kafka 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 StreamsHub 控制台中发现了一个漏洞,该漏洞涉及 Apache Kafka 的流处理控制台。控制台的自定义资源(Console Custom Resource)中由租户提供的 Kafka 客户端属性被直接复制到 console-api 的 AdminClient 配置中,而没有对安全性敏感的配置键进行过滤。这允许控制台自定义资源(Console CR)的编写者设置 和 ,从而将 console-api 服务账号(ServiceAccount)的令牌外泄到攻击者控制的 Kafka Broker 中。

CVSS 6.5 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
Red Hat streams for Apache Kafka 2 any affected
Red Hat streams for Apache Kafka 3 any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96740

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka client properties → sa-token exfiltration via config.providers
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用外部可控制的输入来选择类或代码(不安全的反射)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat streams for Apache Kafka 2 - cpe:/a:redhat:amq_streams:2
Red Hat streams for Apache Kafka 3 - cpe:/a:redhat:amq_streams:3

II. Public POCs for CVE-2026-96740

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96740

请登录查看更多情报信息。

Other References for CVE-2026-96740 (2)

Same Patch Batch · Red Hat · 2026-09-28 · 10 CVEs total

CVE-2026-101292 8.2 HIGH Artemis-core-client: unsafe reflection in apache activemq artemis federation message deser
CVE-2026-86330 7.2 HIGH Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_intern
CVE-2026-97023 7.1 HIGH Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy dir
CVE-2026-87114 7.1 HIGH Kube-compare: container:// reference extraction runs the image entrypoint and silently esc
CVE-2026-102010 7.0 HIGH Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in bina
CVE-2026-97026 3.9 LOW Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path
CVE-2026-101333 3.7 LOW Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on brok
CVE-2026-97027 3.6 LOW Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus
CVE-2026-97025 3.2 LOW Flatpak: flatpak: world-readable oci authentication token in system-helper cache path

IV. Related Vulnerabilities

V. Comments for CVE-2026-96740

No comments yet


Leave a comment