---
id: CVE-2026-92778
title: >-
  CMAK through 3.0.0.6 fails to apply the scheduled leader election feature
  toggle to HTML form routes, allowing attackers to bypass the feature gate
summary: >-
  CMAK through 3.0.0.6 fails to apply the scheduled leader election feature
  toggle to HTML form routes, allowing attackers to bypass the feature gate.
  Attackers can access the form endpoints to start and stop the recurring
  election schedul…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-693
vendor: yahoo
product: CMAK
affected:
  - CMAK <= 3.0.0.6
published: '2026-09-16'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:17:49.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92778'
references:
  - url: 'https://github.com/yahoo/CMAK'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/yahoo/CMAK/blob/3.0.0.6/app/controllers/PreferredReplicaElection.scala#L110-L143
    label: disclosure@vulncheck.com
  - url: 'https://github.com/yahoo/CMAK/issues/936'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/cmak-through-3.0.0.6-feature-gate-bypass-via-html-form-routes
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00441
epssPercentile: 0.35668
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T13:49:41.863587Z'
ingestedAt: '2026-09-16T21:05:36.891Z'
---

## Overview

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
