CVE-2026-96740 Overview
A flaw in the StreamsHub Console for Apache Kafka allows tenant-supplied Kafka client properties from the Console custom resource (CR) to reach the console-api AdminClient configuration without filtering security-sensitive keys. A Console CR author can set config.providers and bootstrap.servers to redirect the client to an attacker-controlled broker and exfiltrate the console-api ServiceAccount token. The weakness is tracked as CWE-470: Use of Externally-Controlled Input to Select Classes or Code.
Critical Impact
Authenticated tenants with permission to create or modify Console custom resources can exfiltrate the console-api Kubernetes ServiceAccount token to an external broker, enabling downstream cluster access.
Affected Products
- StreamsHub Console for Apache Kafka (console-api component)
- Deployments consuming Console custom resources for Kafka client configuration
- Red Hat distributions referencing this component (see vendor advisory)
Discovery Timeline
- 2026-09-28 - CVE-2026-96740 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-96740
Vulnerability Analysis
The StreamsHub Console exposes a custom resource that allows administrators to declare Kafka client properties consumed by the backend console-api. These tenant-supplied properties are copied verbatim into the AdminClient configuration used to talk to Kafka brokers. Because sensitive keys are not filtered, a CR author can override runtime configuration mechanics rather than just supplying benign connection parameters.
Kafka's client libraries support the config.providers mechanism, which loads pluggable providers that can read values from files, environment variables, or directory paths at connection time. When combined with an attacker-controlled bootstrap.servers value, a CR author can point the client at a rogue broker and coerce the client to load and transmit the console-api ServiceAccount token mounted inside the pod.
The result is disclosure of a Kubernetes ServiceAccount credential to an external endpoint over an attacker-selected network path.
Root Cause
The root cause is missing allow-list filtering when merging tenant-supplied properties into the AdminClient configuration. The vulnerable code trusts the CR contents rather than restricting which Kafka client keys a tenant may set. Security-sensitive keys such as config.providers, config.providers.*.class, and bootstrap.servers should have been rejected or namespaced away from tenant control. This aligns with [CWE-470], where externally supplied input selects the code path (a class or provider) that the client executes.
Attack Vector
An attacker requires authenticated access sufficient to create or edit a Console custom resource in the target namespace. The attacker sets bootstrap.servers to a broker they control and defines a config.providers entry that reads the ServiceAccount token file mounted at /var/run/secrets/kubernetes.io/serviceaccount/token. When the console-api instantiates the AdminClient, the provider resolves the token and it is transmitted during connection setup or SASL exchange to the attacker's broker.
Refer to the upstream fix in the StreamsHub Console pull request #2957 for the authoritative technical description.
Detection Methods for CVE-2026-96740
Indicators of Compromise
- Console custom resources containing config.providers, config.providers.*.class, or config.providers.*.param.* keys under Kafka client properties.
- bootstrap.servers values in Console CRs that point to hosts outside the approved Kafka broker allow-list.
- Egress connections from console-api pods to unexpected external hosts, particularly on Kafka broker ports (9092, 9093, 9094).
Detection Strategies
- Audit Kubernetes API server logs for create and update events against StreamsHub Console CRs and diff the client-properties block against a known-good baseline.
- Alert on any Console CR whose properties include config.providers, sasl.jaas.config, or file-path references such as file:///var/run/secrets/.
- Correlate outbound network flows from console-api pods with the declared broker inventory; investigate any destination not on the allow-list.
Monitoring Recommendations
- Enable Kubernetes audit logging at Metadata level or higher for the namespaces hosting StreamsHub Console.
- Forward pod-level network telemetry and Kubernetes audit logs to a centralized analytics platform for correlation across CR changes and egress activity.
- Rotate the console-api ServiceAccount token and review TokenReview and SelfSubjectAccessReview activity for anomalous use following any suspicious CR edit.
How to Mitigate CVE-2026-96740
Immediate Actions Required
- Restrict RBAC on StreamsHub Console custom resources so only trusted operators can create or modify them.
- Review existing Console CRs for config.providers and non-approved bootstrap.servers values and remove them.
- Rotate the console-api ServiceAccount token if any suspicious CR configuration is discovered.
- Apply the upstream fix from streamshub/console PR #2957 once packaged in your distribution.
Patch Information
The upstream remediation filters security-sensitive Kafka client keys before they are merged into the console-api AdminClient configuration. Track vendor availability through the Red Hat CVE Advisory and the associated Red Hat Bug Report. Apply the patched StreamsHub Console release as soon as it is available for your platform.
Workarounds
- Enforce a Kubernetes admission policy (for example, Kyverno or Gatekeeper) that rejects Console CRs containing keys matching config.providers* or sasl.jaas.config.
- Constrain bootstrap.servers values via admission policy to an allow-list of approved brokers.
- Apply a NetworkPolicy that restricts console-api egress to the approved Kafka broker endpoints only, blocking arbitrary external destinations.
- Reduce the privileges of the console-api ServiceAccount to the minimum required, limiting the impact of token disclosure.
# Example Kyverno policy fragment: block sensitive Kafka client keys in Console CRs
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: streamshub-console-block-sensitive-kafka-keys
spec:
validationFailureAction: Enforce
rules:
- name: deny-config-providers
match:
any:
- resources:
kinds:
- Console
validate:
message: "config.providers and sasl.jaas.config are not permitted in Console CRs"
deny:
conditions:
any:
- key: "{{ request.object.spec.kafkaClient.properties.keys(@) }}"
operator: AnyIn
value:
- "config.providers"
- "sasl.jaas.config"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.