PT-2026-94055 · Yahoo+1 · Cmak
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
CMAK versions prior to 3.0.0.7
Description
The software fails to apply the scheduled leader election feature toggle to HTML form routes, which allows attackers to bypass the feature gate. By accessing these form endpoints, an attacker can start and stop the recurring election scheduler, leading to the disruption of leadership across managed Kafka clusters.
Recommendations
Update to version 3.0.0.7 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cmak