Excess RBAC Permissions in Strimzi Kafka Operator on Kubernetes
CVE-2026-55226

5.4MEDIUM

Key Information:

Vendor

Strimzi

Vendor
CVE Published:
15 September 2026

What is CVE-2026-55226?

The Strimzi Kafka Operator on Kubernetes has a vulnerability where deploying either the Topic Operator or User Operator without the other can lead to excessive RBAC permissions. This allows unintended access to sensitive resources such as KafkaUser and KafkaTopic custom resources and Secrets. This issue has been addressed in versions 1.0.1 and 1.1.0, emphasizing the importance of proper deployment configurations to maintain security.

Affected Version(s)

strimzi-kafka-operator < 1.0.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.