Excess RBAC Permissions in Strimzi Kafka Operator on Kubernetes
CVE-2026-55226
5.4MEDIUM
What is CVE-2026-55226?
The Strimzi Kafka Operator on Kubernetes has a vulnerability where deploying either the Topic Operator or User Operator without the other can lead to excessive RBAC permissions. This allows unintended access to sensitive resources such as KafkaUser and KafkaTopic custom resources and Secrets. This issue has been addressed in versions 1.0.1 and 1.1.0, emphasizing the importance of proper deployment configurations to maintain security.
Affected Version(s)
strimzi-kafka-operator < 1.0.1
