Unsafe Deserialization Vulnerability in Kafbat UI for Apache Kafka Clusters
CVE-2025-49127

8.9HIGH

Key Information:

Vendor

Kafbat

Status
Vendor
CVE Published:
6 June 2025

What is CVE-2025-49127?

Kafbat UI, a web interface designed for managing Apache Kafka clusters, contains an unsafe deserialization vulnerability in version 1.0.0. This flaw allows unauthenticated users to execute arbitrary code on the server, posing a significant security risk. The issue has been addressed in version 1.1.0, which mitigates the vulnerability and enhances overall security. Users are strongly advised to upgrade to the latest version immediately to protect their systems against potential exploitation.

Affected Version(s)

kafka-ui = 1.0.0

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.