PT-2026-45725 · Apache · Apache Kafka

·

CVE-2026-41115

·

Published

2026-06-02

·

Updated

2026-06-05

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Kafka (affected versions not specified)
Description An improper authorization issue exists in the 'CONSUMER GROUP DESCRIBE' (69) API. The implementation validates the DESCRIBE operation on the GROUP resource, which contradicts the READ operation specified in the official documentation and KIP-848. This discrepancy can lead to misconfigured Access Control Lists (ACLs), potentially granting READ permissions to unauthorized users or allowing users with only DESCRIBE permissions to access sensitive group metadata.
Recommendations Review existing group ACLs to ensure the principle of least privilege is maintained.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09747
BIT-KAFKA-2026-41115
CVE-2026-41115

Affected Products

Apache Kafka