Skip to content
Red HatCVE-2026-96740

A flaw was found in the StreamsHub Console for Apache Kafka

Medium6.5CVE-2026-96740 · Published Sep 28, 2026 · updated Sep 30, 2026

A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.

Red Hat advisory

Affected versions

PackageAffectedFixed in
StreamsHub Console for Apache Kafka®
Product
>= 0.2.1, < 0.12.90.12.9
>= 0.13.0, < 0.14.10.14.1
streams for Apache Kafka 2
Product
all versionsNo fix yet
streams for Apache Kafka 3
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux: denial of service
Low3.6Sep 28
Flatpak writes the OCI repository authentication token with world-readable...
Low3.2Sep 28
Red Hat Enterprise Linux: denial of service
Low3.9Sep 28
Red Hat Enterprise Linux: path traversal
High7.1Sep 28
Red Hat GCC.: use after free
High7.0Sep 28
Red Hat kube-compare.: remote code execution
High7.1Sep 28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.