PT-2026-7718 · Klaw+1 · Klaw+1

Audrey Budryte

·

Publicado

2026-02-11

·

Atualizado

2026-02-11

·

CVE-2026-25999

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Klaw versions prior to 2.10.2
Description Klaw, a self-service Apache Kafka Topic Management/Governance tool/portal, contains an improper access control issue. This allows unauthorized users to trigger a reset or deletion of metadata for any tenant. An attacker can send a crafted request to the /resetMemoryCache API endpoint to clear cached configurations, environments, and cluster data. The resetMemoryCache function is vulnerable to this manipulation.
Recommendations Update to version 2.10.2 or later.

Exploit

Correção

Improper Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25999
GHSA-RP26-QV9W-XR5Q

Produtos afetados

Apache Kafka
Klaw