Unauthorized Access Vulnerability in Strimzi Kafka Operator
CVE-2026-55225

8HIGH

Key Information:

Vendor

Strimzi

Vendor
CVE Published:
15 September 2026

What is CVE-2026-55225?

The Strimzi Kafka Operator, which enables Apache Kafka deployments on Kubernetes and OpenShift, has a vulnerability that allows attackers to gain unauthorized access to sensitive information. An attacker with the ability to create a Kafka custom resource can manipulate the 'watchedNamespace' setting, leading the Cluster Operator to generate a Role with comprehensive Secret CRUD permissions within their targeted namespace. This role is then incorrectly bound to the Entity Operator ServiceAccount, enabling the attacker to mint tokens and access or modify Secrets indiscriminately across namespaces where the Cluster Operator possesses permissions. The issue is remedied in versions 1.0.1 and 1.1.0.

Affected Version(s)

strimzi-kafka-operator < 1.0.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.