PT-2026-83289 · Redpanda · Redpanda
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Redpanda versions prior to 26.2.3
Description
The Admin API binds to '0.0.0.0:9644' with the
admin api require auth variable defaulting to false. This configuration causes the system to treat unauthenticated requests as superusers, allowing unauthorized access to the Admin API endpoint. An attacker can use this to create or delete broker accounts, modify cluster configurations, and disrupt partition replication.Recommendations
Update Redpanda to version 26.2.3 or later.
Set the
admin api require auth variable to true to require authentication for the Admin API.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redpanda