PT-2025-24331 · Apache+1 · Apache Kafka+1

Trganda

·

Published

2025-01-13

·

Updated

2025-08-20

·

CVE-2025-49127

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kafbat UI version 1.0.0 Kafbat UI versions prior to 1.1.0
Description Kafbat UI is a web user interface designed for managing Apache Kafka clusters. An unsafe deserialization vulnerability exists that allows any unauthenticated user to execute arbitrary code on the server. The issue stems from the application’s dynamic cluster configuration functionality that accepts user-provided JMX endpoints without proper validation.
Recommendations Kafbat UI version 1.0.0: Upgrade to version 1.1.0 or later to resolve this issue. Kafbat UI versions prior to 1.1.0: Upgrade to version 1.1.0 or later to resolve this issue.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-14363
CVE-2025-49127
GHSA-G3MF-C374-FGH2

Affected Products

Apache Kafka
Kafbat Ui