Flaw in StreamsHub Console for Apache Kafka Exposes Sensitive Configuration
CVE-2026-96740

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
28 September 2026

What is CVE-2026-96740?

A security flaw exists in the StreamsHub Console for Apache Kafka that permits the unauthorized manipulation of tenant-supplied Kafka client properties. When these properties are incorporated into the console-api AdminClient configuration without appropriate filtering of sensitive security keys, it creates an avenue for exploitation. Attackers can potentially extract the console-api ServiceAccount token by misconfiguring critical settings such as config.providers and bootstrap.servers, leading to a risk of sensitive information being exfiltrated to an unauthorized broker.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.