An improper authorization vulnerability has been identified in Apache Kafka.
The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata.
The correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.
References
| Link | Resource |
|---|---|
| https://kafka.apache.org/cve-list | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/06/02/5 | Mailing List Third Party Advisory |
Configurations
History
03 Jun 2026, 02:04
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Apache
Apache kafka |
|
| CPE | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* | |
| References | () https://kafka.apache.org/cve-list - Vendor Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2026/06/02/5 - Mailing List, Third Party Advisory |
02 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
02 Jun 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-02 10:16
Updated : 2026-06-03 02:04
NVD link : CVE-2026-41115
Mitre link : CVE-2026-41115
CVE.ORG link : CVE-2026-41115
JSON object : View
Products Affected
apache
- kafka
CWE
CWE-285
Improper Authorization
