---
id: CVE-2026-96740
title: A flaw was found in the StreamsHub Console for Apache Kafka
summary: >-
  A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied
  Kafka client properties from the Console custom resource are copied into the
  console-api AdminClient configuration without filtering security-sensitive
  keys, al…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-470
vendor: Red Hat
product: console-operator
affected:
  - console-operator (all versions)
  - console-operator (all versions)
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T18:17:26.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96740'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-96740'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2539427'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T18:17:54.313Z'
---

## Overview

A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
