Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Restrict `create`, `update`, and `patch` permissions for Console custom resources to trusted administrators only. Where supported, apply a NetworkPolicy to restrict Console API egress to approved Kafka broker endpoints. These controls reduce exposure to the reported ServiceAccount-credential disclosure path but do not replace the permanent fix, which is to filter security-sensitive Kafka client properties. Upgrade to a release containing the permanent fix when available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker. | |
| Title | Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka client properties → sa-token exfiltration via config.providers | |
| First Time appeared |
Redhat
Redhat amq Streams |
|
| Weaknesses | CWE-470 | |
| CPEs | cpe:/a:redhat:amq_streams:2 cpe:/a:redhat:amq_streams:3 |
|
| Vendors & Products |
Redhat
Redhat amq Streams |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-28T17:27:44.240Z
Reserved: 2026-09-23T15:44:19.471Z
Link: CVE-2026-96740
No data.
No data.
No data.
OpenCVE Enrichment
No data.