Executive brief
A vulnerability exists in Provectus kafka-ui, a popular web interface for managing Apache Kafka clusters. An attacker can remotely inject and execute malicious code on the server hosting the application. This could lead to a complete system takeover, unauthorized access to sensitive data within the Kafka clusters, or disruption of business operations.
Technical details
A code injection vulnerability (CWE-94/CWE-74) exists in Provectus kafka-ui versions up to 0.7.2. The flaw is located in the 'validateAccess' function within the '/api/smartfilters/testexecutions' endpoint. An unauthenticated remote attacker can exploit this by sending a specially crafted request to the vulnerable endpoint, leading to arbitrary code execution on the underlying host. While the vendor was notified, no official patch has been confirmed, and a public exploit (PoC) is currently available. NIST has assigned a CVSS score of 9.8, reflecting the high impact and lack of authentication required.
Affected products
- Provectus kafka-ui 0.7.0 to 0.7.2
Timeline
- 2026-04-05: disclosed: Initial disclosure via VulDB and NVD
- 2026-04-05: advisory: CVE-2026-5562 published