CVE-2026-92778 PUBLISHED

CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor yahoo
Product CMAK
Versions Default: unaffected
  • affected from 0 to 3.0.0.6 (incl.)

Credits

  • George Chen finder

References

Problem Types

  • Protection Mechanism Failure CWE