PT-2026-50541 · Maven · Io.Strimzi:Strimzi

Publicado

2026-06-17

·

Atualizado

2026-06-18

·

CVE-2026-55226

CVSS v3.1

5.4

Média

VetorAV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Impact

When only the Topic or only the User operators are deployed as part of the Entity Operator in the Kafka custom resource, the RBAC rights are not following the principle of least-privilege and the Entity Operator ServiceAccount still has access rights corresponding to both operators. That might allow the ServiceAccount to access KafkaUser custom resources and Secrets when the User operator is not deployed and access KafkaTopic custom resources when the Topic operator is not deployed.

Patches

The issue is fixed in Strimzi 1.0.1 and 1.1.0.

Workarounds

There is no workaround for this issue.

Correção

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-55226
GHSA-R427-J2H7-WV3M

Produtos afetados

Io.Strimzi:Strimzi