---
id: CVE-2026-55225
title: >-
  Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or
  OpenShift in various deployment configurations
summary: >-
  Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or
  OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier,
  an attacker who can create a Kafka custom resource can set
  Kafka.spec.entityOperator wat…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-269
  - CWE-441
  - CWE-250
vendor: strimzi
product: strimzi-kafka-operator
affected:
  - strimzi-kafka-operator < 1.0.1
patched:
  - 'io.strimzi:strimzi 1.0.1'
published: '2026-09-15'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T13:18:03.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55225'
references:
  - url: >-
      https://github.com/strimzi/strimzi-kafka-operator/commit/b3bfeffcc30754c3e62e6f4afd8a76942cac440d
    label: security-advisories@github.com
  - url: >-
      https://github.com/strimzi/strimzi-kafka-operator/commit/f6c5207ba7ec89b46ce6720b8638d647e556a261
    label: security-advisories@github.com
  - url: 'https://github.com/strimzi/strimzi-kafka-operator/pull/12844'
    label: security-advisories@github.com
  - url: 'https://github.com/strimzi/strimzi-kafka-operator/releases/tag/1.0.1'
    label: security-advisories@github.com
  - url: 'https://github.com/strimzi/strimzi-kafka-operator/releases/tag/1.1.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/strimzi/strimzi-kafka-operator/security/advisories/GHSA-mw9r-p8xp-wx96
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:54435'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55225'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2490275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55225.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://github.com/advisories/GHSA-mw9r-p8xp-wx96'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55225'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55225'
tags:
  - nvd
  - cve.org
  - ghsa
  - maven
  - csaf
  - vex
  - red-hat
ecosystem: maven
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-15T19:02:30.423631Z'
ingestedAt: '2026-06-29T14:31:47.015Z'
epss: 0.00295
epssPercentile: 0.1974
---

## Overview

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role with full Secret CRUD permissions there and bind it to the Entity Operator ServiceAccount in the attacker's namespace. The attacker can mint a token for that ServiceAccount and read or write Secrets in any target namespace where the Cluster Operator has been granted permissions, regardless of STRIMZI_NAMESPACE. This issue is fixed in versions 1.0.1 and 1.1.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-55225)

Affected packages:

- `io.strimzi:strimzi <= 1.0.0`

Patched in:

- `io.strimzi:strimzi 1.0.1`

Source: https://github.com/advisories/GHSA-mw9r-p8xp-wx96

## Vendor advisories

- **RHSA-2026:54435** · Red Hat · fixed in: Streams for Apache Kafka 3.2.1 · released 2026-08-12 · [advisory](https://access.redhat.com/errata/RHSA-2026:54435)
- **Red Hat VEX** · Important · affected: streams for Apache Kafka 2 · no fix planned: streams for Apache Kafka 2 · updated 2026-09-15 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55225.json)
