← Vulnerability feed

Vulnerability record · CVE-2026-41115 · published 2 June 2026

CVE-2026-41115: Apache kafka improper authorization vulnerability

Apache · Kafka

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata. The correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.

4.3 CVSS 3.1 Medium EPSS 0.45% · top 63.1% CWE-285 · Improper authorization
4.3CVSS 3.1 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
22 Jul 2026Last modified by NVD

Description

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata. The correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://kafka.apache.org/cve-list Vendor Advisory
http://www.openwall.com/lists/oss-security/2026/06/02/5 Mailing ListThird Party Advisory

Track CVE-2026-41115 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-33557Apache kafka vulnerabilityA possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set …EPSS 0.93%8.8CVE-2025-27818Apache kafka deserialization of untrusted data vulnerabilityA possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connec…EPSS 1.0%8.8CVE-2018-17196Apache kafka vulnerabilityIn Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL val…EPSS 5.5%8.7CVE-2026-35554Apache kafka race condition vulnerabilityA race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. W…EPSS 0.65%7.5CVE-2025-27817Apache Kafka Client arbitrary file read and SSRF via SASL/OAUTHBEARER URLsApache Kafka Clients accept SASL/OAUTHBEARER configuration values such as sasl.oauthbearer.token.endpoint.url and sasl.oauthbearer.jwks.endpoint.url,…EPSS 69%analysed7.5CVE-2025-27819Apache kafka deserialization of untrusted data vulnerabilityIn CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka…EPSS 1.0%7.5CVE-2022-34917Apache kafka allocation without limits vulnerabilityA security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated…EPSS 1.5%7.5CVE-2019-12399Apache kafka cleartext transmission vulnerabilityWhen Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a conne…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2026-41115), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.