Feature Gate Bypass Vulnerability in CMAK by Yahoo
CVE-2026-92778

5.3MEDIUM

Key Information:

Vendor

Yahoo

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92778?

The CMAK product, running on version 3.0.0.6, contains a vulnerability that allows attackers to bypass critical scheduled leader election feature toggles in HTML form routes. This oversight enables unauthorized access to form endpoints, permitting attackers to start and stop the recurring election scheduler. As a result, leadership management across Kafka clusters can be disrupted, potentially affecting the stability and security of systems relying on this functionality.

Affected Version(s)

CMAK 0 <= 3.0.0.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.