Junglewise Threat Intelligence

CVE-2026-5562: Provectus kafka-ui code injection in smartfilters endpoint

CVE-2026-5562 · Severity: high · CVSS 7.3 · Published 2026-04-05

Executive brief

A vulnerability exists in Provectus kafka-ui, a popular web interface for managing Apache Kafka clusters. An attacker can remotely inject and execute malicious code on the server hosting the application. This could lead to a complete system takeover, unauthorized access to sensitive data within the Kafka clusters, or disruption of business operations.

Technical details

A code injection vulnerability (CWE-94/CWE-74) exists in Provectus kafka-ui versions up to 0.7.2. The flaw is located in the 'validateAccess' function within the '/api/smartfilters/testexecutions' endpoint. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the vulnerable endpoint, leading to arbitrary code execution on the underlying host. While the vendor was notified, no official patch has been confirmed, and a public exploit (PoC) is currently available. NIST has assigned a CVSS score of 9.8, reflecting the high impact and lack of authentication required.

Affected products

  • Provectus kafka-ui 0.7.0 to 0.7.2

Timeline

  • 2026-04-05: disclosed: Initial disclosure via VulDB and NVD
  • 2026-04-05: advisory: CVE-2026-5562 published

References

Related threats