Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.strimzi/strimzi
  4. ›
  5. CVE-2026-55226

CVE-2026-55226: Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator

June 18, 2026

When only the Topic or only the User operators are deployed as part of the Entity Operator in the Kafka custom resource, the RBAC rights are not following the principle of least-privilege and the Entity Operator ServiceAccount still has access rights corresponding to both operators. That might allow the ServiceAccount to access KafkaUser custom resources and Secrets when the User operator is not deployed and access KafkaTopic custom resources when the Topic operator is not deployed.

References

  • github.com/advisories/GHSA-r427-j2h7-wv3m
  • github.com/strimzi/strimzi-kafka-operator/security/advisories/GHSA-r427-j2h7-wv3m
  • nvd.nist.gov/vuln/detail/CVE-2026-55226

Code Behaviors & Features

Detect and mitigate CVE-2026-55226 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.0.1

Fixed versions

  • 1.0.1

Solution

Upgrade to version 1.0.1 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-269: Improper Privilege Management
  • CWE-272: Least Privilege Violation

Source file

maven/io.strimzi/strimzi/CVE-2026-55226.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 19 Jun 2026 12:16:16 +0000.