mTLS Configuration Flaw in Strimzi for Apache Kafka on Kubernetes
CVE-2026-27134
8.1HIGH
What is CVE-2026-27134?
Strimzi provides a means to run Apache Kafka on Kubernetes or OpenShift. In versions 0.49.0 to 0.50.0, a misconfiguration arises when users employ a custom Cluster or Clients CA with a multistage CA chain. This flaw permits any certificate signed by any CA within the chain to authenticate, potentially jeopardizing the security of the cluster. Users not utilizing the Strimzi-managed CAs or those using a single CA without a chain are unaffected. The issue was resolved in version 0.50.1, and a workaround is available by utilizing only the specific CA intended for authentication rather than the complete CA chain.
Affected Version(s)
strimzi-kafka-operator >= 0.49.0, < 0.50.1
