mTLS Configuration Flaw in Strimzi for Apache Kafka on Kubernetes
CVE-2026-27134

8.1HIGH

Key Information:

Vendor

Strimzi

Vendor
CVE Published:
20 February 2026

What is CVE-2026-27134?

Strimzi provides a means to run Apache Kafka on Kubernetes or OpenShift. In versions 0.49.0 to 0.50.0, a misconfiguration arises when users employ a custom Cluster or Clients CA with a multistage CA chain. This flaw permits any certificate signed by any CA within the chain to authenticate, potentially jeopardizing the security of the cluster. Users not utilizing the Strimzi-managed CAs or those using a single CA without a chain are unaffected. The issue was resolved in version 0.50.1, and a workaround is available by utilizing only the specific CA intended for authentication rather than the complete CA chain.

Affected Version(s)

strimzi-kafka-operator >= 0.49.0, < 0.50.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.