PT-2026-50541 · Maven · Io.Strimzi:Strimzi
Published
2026-06-17
·
Updated
2026-06-18
·
CVE-2026-55226
CVSS v3.1
5.4
Medium
| Vector | AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N |
Impact
When only the Topic or only the User operators are deployed as part of the Entity Operator in the
Kafka custom resource, the RBAC rights are not following the principle of least-privilege and the Entity Operator ServiceAccount still has access rights corresponding to both operators. That might allow the ServiceAccount to access KafkaUser custom resources and Secrets when the User operator is not deployed and access KafkaTopic custom resources when the Topic operator is not deployed.Patches
The issue is fixed in Strimzi 1.0.1 and 1.1.0.
Workarounds
There is no workaround for this issue.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Io.Strimzi:Strimzi