CVE-2023-50976: Redpanda

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API.

Affected products

  • Redpanda Redpanda: before 23.1.21 (fixed in 23.1.21); from 23.2.0, before 23.2.18 (fixed in 23.2.18)

Published 2023-12-18. Last modified 2026-06-17.