https://seclists.org/oss-sec/2026/q3/18: [CVE quest] Apache Kafka OAUTHBEAR authentication bypass via signed JWT clock skew (vulnerable 4.0.0 - 4.0.x, no maintainer sponse in 7 days)
Published Jul 4, 2026
·Updated
Affected Software
1 affected component
Apache Kafka>=4.0.0<=4.0.x
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXXX?
The severity of CVE-2026-XXXXX is considered high due to the potential for unauthorized access via authentication bypass.
2
How do I fix CVE-2026-XXXXX?
To fix CVE-2026-XXXXX, upgrade Apache Kafka to version 4.0.x or later where the vulnerability is addressed.
3
What versions of Apache Kafka are affected by CVE-2026-XXXXX?
CVE-2026-XXXXX affects Apache Kafka versions from 4.0.0 to 4.0.x.
4
What type of vulnerability is CVE-2026-XXXXX?
CVE-2026-XXXXX is categorized as an authentication bypass via signed JWT clock skew.
5
What impact does CVE-2026-XXXXX have on security?
CVE-2026-XXXXX allows attackers to bypass authentication mechanisms, potentially leading to unauthorized data access.