Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41115

Опубликовано: 02 июн. 2026
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

An improper authorization vulnerability has been identified in Apache Kafka.

The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata.

The correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.3.0 (включая)

EPSS

Процентиль: 21%
0.00288
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-285

Связанные уязвимости

CVSS3: 4.3
debian
2 месяца назад

An improper authorization vulnerability has been identified in Apache ...

CVSS3: 4.3
github
около 2 месяцев назад

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata. The correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.

CVSS3: 4.3
fstec
2 месяца назад

Уязвимость реальзиации механизма авторизации API CONSUMER_GROUP_DESCRIBE диспетчера сообщений Apache Kafka, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
redos
25 дней назад

Уязвимость apache-kafka

EPSS

Процентиль: 21%
0.00288
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-285