CVE-2026-96740: Red Hat Streams For Apache Kafka 2
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.
Affected products
- Red Hat Streams For Apache Kafka 2
- Red Hat Streams For Apache Kafka 3
- Red Hat Streamshub Console For Apache Kafka: from 0.2.1, before 0.12.9 (fixed in 0.12.9); from 0.13.0, before 0.14.1 (fixed in 0.14.1)
Published 2026-09-28. Last modified 2026-10-05.