Unauthorized Access Vulnerability in Strimzi Kafka Operator
CVE-2026-55225
8HIGH
What is CVE-2026-55225?
The Strimzi Kafka Operator, which enables Apache Kafka deployments on Kubernetes and OpenShift, has a vulnerability that allows attackers to gain unauthorized access to sensitive information. An attacker with the ability to create a Kafka custom resource can manipulate the 'watchedNamespace' setting, leading the Cluster Operator to generate a Role with comprehensive Secret CRUD permissions within their targeted namespace. This role is then incorrectly bound to the Entity Operator ServiceAccount, enabling the attacker to mint tokens and access or modify Secrets indiscriminately across namespaces where the Cluster Operator possesses permissions. The issue is remedied in versions 1.0.1 and 1.1.0.
Affected Version(s)
strimzi-kafka-operator < 1.0.1
