Junglewise Threat Intelligence

CVE-2026-41115: Apache Kafka improper authorization in CONSUMER_GROUP_DESCRIBE API

CVE-2026-41115 · Severity: info · CVSS 0 · Published 2026-06-02

Vendors: Apache.

Executive brief

Apache Kafka is a widely used platform for handling real-time data streams and messaging between applications. A documentation discrepancy was found where the system requires 'DESCRIBE' permissions to access group metadata, even though official guides suggested 'READ' permissions were required. This could lead to situations where users have more or less access to sensitive group information than intended by administrators who followed the incorrect documentation.

Technical details

An improper authorization vulnerability exists in Apache Kafka due to a discrepancy between the implementation of the CONSUMER_GROUP_DESCRIBE (69) API and its documentation. The API validates the DESCRIBE operation on the GROUP resource, whereas official documentation and KIP-848 incorrectly stated that the READ operation was required. This mismatch can result in unintended security postures: users with DESCRIBE permissions may access sensitive group metadata without having READ permissions, or users granted READ permissions specifically to access this API may find they lack the necessary DESCRIBE rights. The vendor has clarified that DESCRIBE is the intended requirement and will update documentation accordingly; users are advised to audit their ACLs to ensure the principle of least privilege is maintained.

Affected products

  • Apache Kafka

Timeline

  • 2026-06-02: disclosed
  • 2026-06-02: advisory

References

Related threats