MEDIUM 5.3 NVD
CVE-2026-92778
CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers c
CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.
References
- https://github.com/yahoo/CMAK
- https://github.com/yahoo/CMAK/blob/3.0.0.6/app/controllers/PreferredReplicaElection.scala#
- https://github.com/yahoo/CMAK/issues/936
- https://www.vulncheck.com/advisories/cmak-through-3.0.0.6-feature-gate-bypass-via-html-for
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.