PT-2026-7718 · Klaw+1 · Klaw+1

Audrey Budryte

·

Published

2026-02-11

·

Updated

2026-02-11

·

CVE-2026-25999

CVSS v3.1

7.1

High

AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Klaw versions prior to 2.10.2
Description Klaw, a self-service Apache Kafka Topic Management/Governance tool/portal, contains an improper access control issue. This allows unauthorized users to trigger a reset or deletion of metadata for any tenant. An attacker can send a crafted request to the /resetMemoryCache API endpoint to clear cached configurations, environments, and cluster data. The resetMemoryCache function is vulnerable to this manipulation.
Recommendations Update to version 2.10.2 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-25999
GHSA-RP26-QV9W-XR5Q

Affected Products

Apache Kafka
Klaw