Code Injection Vulnerability in Provectus Kafka-UI by Provectus
CVE-2026-78166
Key Information:
Badges
What is CVE-2026-78166?
A security flaw exists in the Apache Kafka user interface provided by Provectus, specifically in the executeSmartFilterTest function within the Groovy Code Handler. This vulnerability permits an attacker to inject malicious code remotely, leading to potential unauthorized access and manipulation of the application. The flaw impacts versions up to 0.7.2, and despite early notification to the project maintainers, an official response has not yet been documented. Given the release of the exploit into the public domain, immediate mitigation and patching are advised to safeguard systems.
Affected Version(s)
kafka-ui 0.7.0
kafka-ui 0.7.1
kafka-ui 0.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
