CVE-2025-49127: Kafbat UI vulnerable to Remote Code Execution by JMX in Metrices Configuration
Published Jun 6, 2025
·Updated
Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute arbitrary code on the server. Version 1.1.0 fixes the issue.
Affected Software
1 affected component
Kafbat Kafbat UI
Event History
Jun 6, 2025
CVE Published
via MITRE·08:23 PM
Data Sourced
via MITRE·08:23 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49127?
The severity of CVE-2025-49127 is critical due to its potential for unauthenticated remote code execution.
2
How do I fix CVE-2025-49127?
To fix CVE-2025-49127, upgrade to Kafbat UI version 1.1.0 or later.
3
Who is affected by CVE-2025-49127?
CVE-2025-49127 affects users of Kafbat UI version 1.0.0.
4
What type of vulnerability is CVE-2025-49127?
CVE-2025-49127 is an unsafe deserialization vulnerability.
5
Can CVE-2025-49127 be exploited by unauthenticated users?
Yes, CVE-2025-49127 can be exploited by any unauthenticated user.