Impact
CMAK versions through 3.0.0.6 apply an optional feature toggle that controls a recurring leader election scheduler for Kafka clusters. The vulnerability in these releases prevents the toggle from being enforced on the HTML form endpoints that start or stop the scheduler. An attacker who can reach these form routes can therefore bypass the intended restriction, enabling the scheduler to run or be stopped arbitrarily. This capability can disrupt leadership elections and cause availability outages in the dependent Kafka clusters, matching the CWE‑693 category of system component failure.
Affected Systems
Yahoo CMAK versions up to and including 3.0.0.6 are affected. All deployments that expose the CMAK web interface without additional access controls for the election scheduler endpoints are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate overall risk, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, further indicating a lower threat level. The likely attack vector is through remote access to the CMAK web interface, and it is inferred that an attacker would need to authenticate or otherwise bypass any network restrictions to reach the form endpoints. Because the impact is primarily a denial of service to Kafka cluster leadership, the risk is confined to service availability rather than confidentiality or integrity.
OpenCVE Enrichment