Description
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom resource leaves the Entity Operator ServiceAccount with RBAC permissions for both components. The excess permissions can allow access to KafkaUser custom resources and Secrets when the User Operator is absent, or access to KafkaTopic custom resources when the Topic Operator is absent. This issue is fixed in versions 1.0.1 and 1.1.0.
Published: 2026-09-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass: Unrestricted Secret Access
Action: Patch
AI Analysis

Impact

Strimzi 1.0.0 and earlier provide the Entity Operator ServiceAccount with RBAC permissions for both the Topic Operator and the User Operator, even when only one component is enabled via the Kafka custom resource. This over‑permissive policy allows the ServiceAccount to read KafkaUser custom resources and the Secrets associated with them when the User Operator is not deployed, or to read KafkaTopic custom resources when the Topic Operator is absent. Attackers can exploit this to retrieve sensitive configuration data, such as connection credentials, from Secrets stored in the namespace. The flaw constitutes an authorization bypass that compromises confidentiality of data within the namespace, potentially affecting multiple users or applications consuming those secrets.

Affected Systems

The vulnerability affects Strimzi Kafka Operator versions 1.0.0 and earlier. When deploying only the Topic Operator or only the User Operator through the Kafka custom resource, the Entity Operator ServiceAccount retains permissions for both components. The fix is available in releases 1.0.1 and 1.1.0.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate impact and complexity. EPSS is reported as less than 1%, suggesting a low probability of active exploitation. The CVE is not listed in the CISA KEV catalog. An attacker must be able to access a pod or process that has the Entity Operator ServiceAccount token within the same namespace. By using that token, the attacker can read Secret objects and custom resources, potentially exposing sensitive information to any user or application with that token.

Generated by OpenCVE AI on September 20, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Strimzi Cluster Operator to at least version 1.0.1 or 1.1.0 to remove the over‑permissive RBAC rules.
  • Re‑evaluate and limit the RoleBinding or ClusterRoleBinding objects that grant access to the Entity Operator ServiceAccount, ensuring they only give permissions for operators that are actually deployed. Temporarily disable or remove role bindings for the operator that is not enabled.
  • If upgrade cannot be applied immediately, revoke any RBAC that grants the Entity Operator ServiceAccount permissions for the unused operator and enable audit logging to monitor for unauthorized Secret reads.

Generated by OpenCVE AI on September 20, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r427-j2h7-wv3m Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description When deploying only the Topic Operator or only the User Operator via the Kafka custom resource, the Entity Operator's ServiceAccount retains RBAC rights for both operators rather than scoping permissions to the one actually deployed. This allows the ServiceAccount to access KafkaUser custom resources and Secrets even when the User Operator is not deployed, or access KafkaTopic custom resources when the Topic Operator is not deployed, violating the principle of least privilege. There is no workaround for this issue. Fixed in Strimzi 1.0.1 and 1.1.0. Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom resource leaves the Entity Operator ServiceAccount with RBAC permissions for both components. The excess permissions can allow access to KafkaUser custom resources and Secrets when the User Operator is absent, or access to KafkaTopic custom resources when the Topic Operator is absent. This issue is fixed in versions 1.0.1 and 1.1.0.
Title strimzi-cluster-operator: Unrestricted access to all Secrets within namespace watched by the Topic operator in Strimzi Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
Weaknesses CWE-269
References

Wed, 24 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Strimzi
Strimzi kafka-operator
Vendors & Products Strimzi
Strimzi kafka-operator

Fri, 19 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
Description When deploying only the Topic Operator or only the User Operator via the Kafka custom resource, the Entity Operator's ServiceAccount retains RBAC rights for both operators rather than scoping permissions to the one actually deployed. This allows the ServiceAccount to access KafkaUser custom resources and Secrets even when the User Operator is not deployed, or access KafkaTopic custom resources when the Topic Operator is not deployed, violating the principle of least privilege. There is no workaround for this issue. Fixed in Strimzi 1.0.1 and 1.1.0.
Title strimzi-cluster-operator: Unrestricted access to all Secrets within namespace watched by the Topic operator in Strimzi
Weaknesses CWE-272
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N'}

threat_severity

Moderate


Subscriptions

Strimzi Kafka-operator
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T15:02:50.239Z

Reserved: 2026-06-16T16:16:32.628Z

Link: CVE-2026-55226

cve-icon Vulnrichment

Updated: 2026-09-16T15:02:47.240Z

cve-icon NVD

Status : Received

Published: 2026-09-15T18:17:23.807

Modified: 2026-09-16T16:17:09.250

Link: CVE-2026-55226

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-17T00:00:00Z

Links: CVE-2026-55226 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:15:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-272

    Least Privilege Violation