Feature Gate Bypass Vulnerability in CMAK by Yahoo
CVE-2026-92778
5.3MEDIUM
What is CVE-2026-92778?
The CMAK product, running on version 3.0.0.6, contains a vulnerability that allows attackers to bypass critical scheduled leader election feature toggles in HTML form routes. This oversight enables unauthorized access to form endpoints, permitting attackers to start and stop the recurring election scheduler. As a result, leadership management across Kafka clusters can be disrupted, potentially affecting the stability and security of systems relying on this functionality.
Affected Version(s)
CMAK 0 <= 3.0.0.6
