CVE-2026-55226Medium· 5.4▾ SunlitStrimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom res…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom resource leaves the Entity Operator ServiceAccount with RBAC permissions for both components. The excess permissions can allow access to KafkaUser custom resources and Secrets when the User Operator is absent, or access to KafkaTopic custom resources when the Topic Operator is absent. This issue is fixed in versions 1.0.1 and 1.1.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
io.strimzi:strimzi <= 1.0.0Patched in:
io.strimzi:strimzi 1.0.1Source: https://github.com/advisories/GHSA-r427-j2h7-wv3m
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55225High· 8.0Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations
CVE-2026-64753Medium· 6.5A permissions issue was addressed by removing the vulnerable code
CVE-2026-77968High· 8.2A flaw was found in hawtio-operator
CVE-2026-73269Critical· 9.9A flaw was found in the cluster-curator-controller component
CVE-2026-54168Medium· 6.5Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories
CVE-2026-54099High· 8.8A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform