Threats Tagged 'cve-2026-96740'
View all threats tagged with 'cve-2026-96740'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-96740'
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in the StreamsHub Console for Apache Kafka allows a Console custom resource author to exfiltrate the console-api ServiceAccount token by setting certain Kafka client properties without filtering security-sensitive keys. This flaw enables unauthorized disclosure of sensitive credentials to an attacker-controlled Kafka broker. The issue is due to tenant-supplied Kafka client properties being copied directly into the console-api AdminClient configuration without proper filtering. Join the discussion | GCVE Database | 09/28/2026, 18:31:27 UTC Added: 09/29/2026, 04:42:07 UTC |
A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to exfiltrate the console-api ServiceAccount token to an attacker-controlled broker. Join the discussion | CVE Database V5 | 09/28/2026, 17:27:44 UTC Added: 09/28/2026, 17:48:23 UTC |
Showing 1 to 2 of 2 results