---
id: CVE-2025-66623
title: >-
  Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or
  OpenShift in various deployment configurations
summary: >-
  Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or
  OpenShift in various deployment configurations. From 0.47.0 and prior to
  0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which
  grants the Apa…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-200
  - CWE-863
vendor: linuxfoundation
product: strimzi
affected:
  - strimzi < 0.49.1
patched:
  - strimzi 0.49.1
published: '2025-12-05'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66623'
references:
  - url: >-
      https://github.com/strimzi/strimzi-kafka-operator/commit/c8a14935e99c91eb0dd865431f46515da9f82ccc
    label: security-advisories@github.com
  - url: >-
      https://github.com/strimzi/strimzi-kafka-operator/security/advisories/GHSA-xrhh-hx36-485q
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00172
epssPercentile: 0.05869
ingestedAt: '2026-09-25T23:21:16.899Z'
---

## Overview

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 and prior to 0.49.1, in some situations, Strimzi creates an incorrect Kubernetes Role which grants the Apache Kafka Connect and Apache Kafka MirrorMaker 2 operands the GET access to all Kubernetes Secrets that exist in the given Kubernetes namespace. The issue is fixed in Strimzi 0.49.1.

## Affected

- `strimzi < 0.49.1`

## Remediation

Upgrade past the affected range:

- `strimzi 0.49.1`
