Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55226

Опубликовано: 17 июн. 2026
Источник: redhat
CVSS3: 5.4

Описание

When deploying only the Topic Operator or only the User Operator via the Kafka custom resource, the Entity Operator's ServiceAccount retains RBAC rights for both operators rather than scoping permissions to the one actually deployed. This allows the ServiceAccount to access KafkaUser custom resources and Secrets even when the User Operator is not deployed, or access KafkaTopic custom resources when the Topic Operator is not deployed, violating the principle of least privilege. There is no workaround for this issue. Fixed in Strimzi 1.0.1 and 1.1.0.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
streams for Apache Kafka 2cluster-operatorFix deferred
streams for Apache Kafka 3cluster-operatorFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-272
https://bugzilla.redhat.com/show_bug.cgi?id=2490660strimzi-cluster-operator: Unrestricted access to all Secrets within namespace watched by the Topic operator in Strimzi

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
github
около 2 месяцев назад

Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator

5.4 Medium

CVSS3