Skip to main content
Vulnerability Database/CVE-2026-55225

CVE-2026-55225: Strimzi Privilege Escalation Vulnerability

CVE-2026-55225 is a privilege escalation flaw in Strimzi that allows attackers with Kafka custom resource creation rights to gain unauthorized access to Secrets across namespaces. This post covers technical details, affected versions, impact assessment, and mitigation strategies.

Updated:

CVE-2026-55225 Overview

CVE-2026-55225 is a privilege escalation vulnerability in Strimzi, the Kubernetes operator for running Apache Kafka clusters on Kubernetes and OpenShift. The flaw exists in Strimzi versions 1.0.0 and earlier. An attacker who can create a Kafka custom resource can abuse the Kafka.spec.entityOperator.watchedNamespace field to point the Cluster Operator at any target namespace. The Cluster Operator then provisions a Role granting full Secret CRUD access in that namespace and binds it to the Entity Operator ServiceAccount in the attacker's namespace. This bypasses the STRIMZI_NAMESPACE isolation boundary. The issue is fixed in versions 1.0.1 and 1.1.0.

Critical Impact

A tenant with permission to create Kafka custom resources can read or write Secrets across every namespace the Cluster Operator manages, exposing credentials, TLS keys, and service tokens cluster-wide.

Affected Products

  • Strimzi Kafka Operator versions 1.0.0 and earlier
  • Red Hat Streams for Apache Kafka (see RHSA-2026:54435)
  • Kubernetes and OpenShift deployments using vulnerable Strimzi versions

Discovery Timeline

  • 2026-09-15 - CVE-2026-55225 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-55225

Vulnerability Analysis

The vulnerability is a privilege escalation flaw classified under [CWE-269] Improper Privilege Management and [CWE-250] Execution with Unnecessary Privileges. The Strimzi Cluster Operator reconciles Kafka custom resources and provisions supporting RBAC objects for the Entity Operator, which manages Kafka topics and users. The operator honors the user-supplied watchedNamespace value on Kafka.spec.entityOperator without validating that the requesting tenant has any authority over the referenced namespace.

When the Cluster Operator processes a malicious Kafka resource, it creates a Role in the target namespace granting get, list, watch, create, update, patch, and delete on secrets. It then creates a RoleBinding linking that Role to the Entity Operator ServiceAccount located in the attacker's own namespace. The attacker can subsequently mint a token for that ServiceAccount and read or modify Secrets across any namespace the Cluster Operator is authorized to manage, regardless of the STRIMZI_NAMESPACE configuration.

Root Cause

The root cause is the absence of an authorization check on the watchedNamespace value supplied through the Kafka custom resource. The Entity Operator watched-namespace feature was enabled by default and did not require operator-level opt-in. The fix introduces a new STRIMZI_ENTITY_OPERATOR_WATCHED_NAMESPACE_ENABLED configuration flag, defaulting to false, that must be explicitly enabled by the cluster administrator.

Attack Vector

Exploitation requires an authenticated tenant with permission to create or modify Kafka custom resources in a single namespace managed by the Cluster Operator. The attacker sets spec.entityOperator.topicOperator.watchedNamespace or spec.entityOperator.userOperator.watchedNamespace to a victim namespace. Once the Cluster Operator reconciles the resource, the attacker requests a token for the Entity Operator ServiceAccount and uses it to enumerate or overwrite Secrets in the targeted namespace.

java
// Security patch: ClusterOperatorConfig.java
// Adds an operator-level opt-in flag for the Entity Operator watched-namespace feature.
public static final ConfigParameter<Boolean> POD_DISRUPTION_BUDGET_GENERATION = new ConfigParameter<>("STRIMZI_POD_DISRUPTION_BUDGET_GENERATION", BOOLEAN, "true", CONFIG_VALUES);

/**
 * Set true to enable watched namespace feature for Entity Operators (Topic Operator and User Operator)
 */
public static final ConfigParameter<Boolean> ENTITY_OPERATOR_WATCHED_NAMESPACE_ENABLED = new ConfigParameter<>("STRIMZI_ENTITY_OPERATOR_WATCHED_NAMESPACE_ENABLED", BOOLEAN, "false", CONFIG_VALUES);

/**
 * The configured Kafka versions
 */

Source: GitHub Commit b3bfeff

Detection Methods for CVE-2026-55225

Indicators of Compromise

  • Role objects granting secrets verbs [get, list, watch, create, update, patch, delete] created in namespaces outside the tenant's expected scope
  • RoleBinding objects binding cross-namespace ServiceAccount subjects (Entity Operator SA in one namespace, Role in another) to Secret permissions
  • Kafka custom resources whose spec.entityOperator.topicOperator.watchedNamespace or spec.entityOperator.userOperator.watchedNamespace field references a namespace the submitting tenant does not own
  • Unexpected TokenRequest API calls against Entity Operator ServiceAccount objects followed by secrets reads in unrelated namespaces

Detection Strategies

  • Audit the Kubernetes API server log for create events on kafkas.kafka.strimzi.io and alert when watchedNamespace differs from the resource's own namespace
  • Enforce OPA Gatekeeper or Kyverno policies that reject Kafka resources with a cross-namespace watchedNamespace value
  • Baseline the set of Role/RoleBinding objects the Cluster Operator normally creates and alert on new bindings targeting secrets resources in sensitive namespaces

Monitoring Recommendations

  • Continuously monitor Kubernetes RBAC changes made by the Cluster Operator ServiceAccount and correlate them with the originating Kafka custom resource
  • Ingest Kubernetes audit logs into a centralized analytics pipeline to correlate TokenRequest, RoleBinding creation, and cross-namespace secrets access patterns
  • Track the Strimzi Cluster Operator version deployed in each cluster and alert on any instance running 1.0.0 or earlier

How to Mitigate CVE-2026-55225

Immediate Actions Required

  • Upgrade the Strimzi Cluster Operator to version 1.0.1 or 1.1.0 in every cluster
  • Enumerate existing Kafka custom resources and review any non-empty spec.entityOperator.*.watchedNamespace values for legitimacy
  • Rotate Secrets in namespaces that the Cluster Operator can manage if unauthorized cross-namespace Role/RoleBinding objects are identified
  • Revoke or restrict RBAC permissions that allow untrusted tenants to create Kafka custom resources

Patch Information

The fix is available in Strimzi releases v1.0.1 and v1.1.0, delivered through Pull Request #12844 and commits b3bfeff and f6c5207. The patch introduces the STRIMZI_ENTITY_OPERATOR_WATCHED_NAMESPACE_ENABLED configuration parameter, which defaults to false, disabling the watched-namespace feature unless explicitly enabled by the operator administrator. Red Hat customers should apply RHSA-2026:54435. Additional context is available in the GitHub Security Advisory GHSA-mw9r-p8xp-wx96.

Workarounds

  • Remove create, update, and patch permissions on kafkas.kafka.strimzi.io from untrusted tenants until the upgrade is completed
  • Deploy an admission controller policy (Kyverno or OPA Gatekeeper) that rejects Kafka resources whose entityOperator.*.watchedNamespace differs from the resource's namespace
  • Constrain the Cluster Operator's RBAC scope to the minimum set of namespaces required, reducing the blast radius of the cross-namespace binding
bash
# Kyverno policy example: block cross-namespace watchedNamespace on Kafka resources
cat <<'EOF' | kubectl apply -f -
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: block-strimzi-cross-namespace-watched
spec:
  validationFailureAction: Enforce
  rules:
    - name: entity-operator-watched-namespace-must-match
      match:
        any:
          - resources:
              kinds:
                - kafka.strimzi.io/v1beta2/Kafka
      validate:
        message: "entityOperator.watchedNamespace must equal the Kafka resource namespace"
        deny:
          conditions:
            any:
              - key: "{{ request.object.spec.entityOperator.topicOperator.watchedNamespace || request.namespace }}"
                operator: NotEquals
                value: "{{ request.namespace }}"
              - key: "{{ request.object.spec.entityOperator.userOperator.watchedNamespace || request.namespace }}"
                operator: NotEquals
                value: "{{ request.namespace }}"
EOF

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.