{"id":"CVE-2026-55225","title":"Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations","summary":"Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator wat…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-269","CWE-441","CWE-250"],"vendor":"strimzi","product":"strimzi-kafka-operator","affected":["strimzi-kafka-operator < 1.0.1"],"patched":["io.strimzi:strimzi 1.0.1"],"published":"2026-09-15","updated":"2026-09-16","sourceUpdated":"2026-09-16T13:18:03.010","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55225","references":[{"url":"https://github.com/strimzi/strimzi-kafka-operator/commit/b3bfeffcc30754c3e62e6f4afd8a76942cac440d","label":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/commit/f6c5207ba7ec89b46ce6720b8638d647e556a261","label":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/pull/12844","label":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/releases/tag/1.0.1","label":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/releases/tag/1.1.0","label":"security-advisories@github.com"},{"url":"https://github.com/strimzi/strimzi-kafka-operator/security/advisories/GHSA-mw9r-p8xp-wx96","label":"security-advisories@github.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:54435","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-55225","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490275","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55225.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://github.com/advisories/GHSA-mw9r-p8xp-wx96"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-55225"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55225"}],"tags":["nvd","cve.org","ghsa","maven","csaf","vex","red-hat"],"ecosystem":"maven","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-15T19:02:30.423631Z"},"ingestedAt":"2026-06-29T14:31:47.015Z","epss":0.0019,"epssPercentile":0.08872,"slug":"CVE-2026-55225","body":"## Overview\n\nStrimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role with full Secret CRUD permissions there and bind it to the Entity Operator ServiceAccount in the attacker's namespace. The attacker can mint a token for that ServiceAccount and read or write Secrets in any target namespace where the Cluster Operator has been granted permissions, regardless of STRIMZI_NAMESPACE. This issue is fixed in versions 1.0.1 and 1.1.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-55225)\n\nAffected packages:\n\n- `io.strimzi:strimzi <= 1.0.0`\n\nPatched in:\n\n- `io.strimzi:strimzi 1.0.1`\n\nSource: https://github.com/advisories/GHSA-mw9r-p8xp-wx96\n\n## Vendor advisories\n\n- **RHSA-2026:54435** · Red Hat · fixed in: Streams for Apache Kafka 3.2.1 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54435)\n- **Red Hat VEX** · Important · affected: streams for Apache Kafka 2 · no fix planned: streams for Apache Kafka 2 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55225.json)","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}