A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.

Project Subscriptions

Vendors Products
Amq Streams Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Restrict `create`, `update`, and `patch` permissions for Console custom resources to trusted administrators only. Where supported, apply a NetworkPolicy to restrict Console API egress to approved Kafka broker endpoints. These controls reduce exposure to the reported ServiceAccount-credential disclosure path but do not replace the permanent fix, which is to filter security-sensitive Kafka client properties. Upgrade to a release containing the permanent fix when available.

History

Mon, 28 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.
Title Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka client properties → sa-token exfiltration via config.providers
First Time appeared Redhat
Redhat amq Streams
Weaknesses CWE-470
CPEs cpe:/a:redhat:amq_streams:2
cpe:/a:redhat:amq_streams:3
Vendors & Products Redhat
Redhat amq Streams
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-28T17:27:44.240Z

Reserved: 2026-09-23T15:44:19.471Z

Link: CVE-2026-96740

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses