Description
CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

CMAK versions through 3.0.0.6 apply an optional feature toggle that controls a recurring leader election scheduler for Kafka clusters. The vulnerability in these releases prevents the toggle from being enforced on the HTML form endpoints that start or stop the scheduler. An attacker who can reach these form routes can therefore bypass the intended restriction, enabling the scheduler to run or be stopped arbitrarily. This capability can disrupt leadership elections and cause availability outages in the dependent Kafka clusters, matching the CWE‑693 category of system component failure.

Affected Systems

Yahoo CMAK versions up to and including 3.0.0.6 are affected. All deployments that expose the CMAK web interface without additional access controls for the election scheduler endpoints are at risk.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate overall risk, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, further indicating a lower threat level. The likely attack vector is through remote access to the CMAK web interface, and it is inferred that an attacker would need to authenticate or otherwise bypass any network restrictions to reach the form endpoints. Because the impact is primarily a denial of service to Kafka cluster leadership, the risk is confined to service availability rather than confidentiality or integrity.

Generated by OpenCVE AI on September 17, 2026 at 23:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CMAK to a version in which the feature toggle is enforced on the HTML form routes.
  • Restrict or disable the election‑scheduler form endpoints via firewall rules or application‑level access controls so that only trusted administrators can invoke them.
  • Implement authentication and role‑based access control for the CMAK web interface to limit exposure to authorized personnel.

Generated by OpenCVE AI on September 17, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Yahoo
Yahoo cmak
Vendors & Products Yahoo
Yahoo cmak

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.
Title CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-17T13:56:26.186Z

Reserved: 2026-09-16T19:22:52.708Z

Link: CVE-2026-92778

cve-icon Vulnrichment

Updated: 2026-09-17T13:49:51.482Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:26.690

Modified: 2026-09-23T17:17:49.217

Link: CVE-2026-92778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:27Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure