CVE-2026-44367

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue has been patched in version 2.10.4.
Configurations

No configuration.

History

22 Jul 2026, 19:10

Type Values Removed Values Added
Summary
  • (es) Klaw es una herramienta/portal de autogestión/gobernanza de temas de Apache Kafka. Antes de la versión 2.10.4, existe una vulnerabilidad en los mecanismos de registro y de inicio de sesión de usuarios debido a un manejo inconsistente de la distinción entre mayúsculas y minúsculas en los nombres de usuario, lo que lleva a una denegación de servicio (DoS) dirigida y un bloqueo completo de la cuenta. Este problema ha sido parcheado en la versión 2.10.4.

02 Jun 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 16:16

Updated : 2026-07-22 19:10


NVD link : CVE-2026-44367

Mitre link : CVE-2026-44367

CVE.ORG link : CVE-2026-44367


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-178

Improper Handling of Case Sensitivity