CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.
References
Configurations
No configuration.
History
16 Sep 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 21:17
Updated : 2026-09-17 14:17
NVD link : CVE-2026-92778
Mitre link : CVE-2026-92778
CVE.ORG link : CVE-2026-92778
JSON object : View
Products Affected
No product.
CWE
CWE-693
Protection Mechanism Failure
