Sceawere

Vulnerability Detail

CVE-2026-96740UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

StreamsHub Console Kafka Configuration Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Red Hat
Product
StreamsHub Console for Apache Kafka®
Attack Type
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-28T18:17:26.880Z",
  "pubdate": "2026-09-28T18:17:26.880Z",
  "executiveSummary": "This vulnerability is an improper input validation flaw within the StreamsHub Console for Apache Kafka, specifically concerning the handling of Kafka client configuration properties.\nThe vulnerability allows a malicious actor with the authority to define or modify a Console custom resource to inject arbitrary configuration parameters into the console-api internal AdminClient.\nBy manipulating security-sensitive keys such as 'config.providers' and 'bootstrap.servers', an attacker can force the application to interact with an external, attacker-controlled broker.\nThis exploitation flow enables the exfiltration of the console-api ServiceAccount token, potentially leading to unauthorized access to the underlying Kubernetes environment or integrated infrastructure.\nThe risk is critical for multi-tenant environments where the definition of Console custom resources is delegated to users with restricted privileges.\nSuccessful exploitation requires the ability to submit or update a Console custom resource within the cluster.\nThe impact includes full compromise of the ServiceAccount credentials used by the console-api, facilitating lateral movement or privilege escalation within the Kafka management ecosystem.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure serialization and propagation of Kafka client properties from the Console custom resource definition to the console-api backend.\nThe application processes client configurations by taking user-supplied input from the custom resource and passing it directly into the AdminClient initialization logic without implementing an allow-list or filter for sensitive configuration keys.\nSpecifically, the 'config.providers' property can be leveraged to load malicious provider classes or force the client to resolve secrets through unauthorized external sources. Furthermore, the 'bootstrap.servers' property allows an attacker to define the destination endpoint for the Kafka client connection.\nThe attack flow proceeds as follows: First, an attacker creates or modifies a Console custom resource, inserting malicious entries into the client properties object. Second, the console-api controller reconciles this resource and initiates the AdminClient, passing the unfiltered configuration parameters.\nThird, upon the instantiation of the AdminClient, the console-api attempts to establish a connection to the 'bootstrap.servers' address defined in the payload. During the connection handshake or subsequent authentication phases, the console-api authenticates using the environment's resident ServiceAccount token.\nFourth, by directing this traffic to an attacker-controlled broker, the attacker captures the ServiceAccount token transmitted as part of the connection request or SASL authentication mechanism.\nThe affected component is the integration layer responsible for mapping the Console custom resource configuration to the underlying Apache Kafka AdminClient implementation. Because the application logic fails to sanitize these inputs, it treats client-provided data as trusted configuration parameters. This effectively grants the attacker control over the connection lifecycle of the console-api service.\nPost-exploitation, the attacker possesses a valid ServiceAccount token, which typically holds enough permissions to query the Kubernetes API, access other secrets, or manipulate pods within the namespace. This vulnerability effectively bypasses intended namespace isolation by leveraging the privilege escalation potential of the console-api’s own service identity."
}
CVE-2026-96740: StreamsHub Console Kafka Configuration Injection (MEDIUM Severity, CVSS: 6.5) | Sceawere