PT-2026-83289 · Redpanda · Redpanda

·

CVE-2026-82266

·

Published

2026-08-28

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Redpanda versions prior to 26.2.3
Description The Admin API binds to '0.0.0.0:9644' with the admin api require auth variable defaulting to false. This configuration causes the system to treat unauthenticated requests as superusers, allowing unauthorized access to the Admin API endpoint. An attacker can use this to create or delete broker accounts, modify cluster configurations, and disrupt partition replication.
Recommendations Update Redpanda to version 26.2.3 or later. Set the admin api require auth variable to true to require authentication for the Admin API.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82266

Affected Products

Redpanda