CVE Tools

CVE-2026-5562

provectus kafka-ui Endpoint testexecutions validateAccess code injection

Published: Apr 5, 2026Updated: Jul 24, 2026 Sources: CVE List NVDCWE-74

Description

A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

In plain language

AI Worth attention

kafka-ui versions up to 0.7.2 have a remotely reachable code-injection flaw; small businesses using it should limit access and seek a vendor fix.

Executive summary

Unauthenticated remote code injection in kafka-ui’s `/api/smartfilters/testexecutions` endpoint through the `validateAccess` function.

If affected, business impact
Kafka UI data exposureUnauthorized UI changesKafka operations disruption

What to do now

  1. Check whether you run kafka-ui up to version 0.7.2 and whether its web interface is reachable from outside your trusted network.
  2. There is currently no vendor-fixed version available; contact your software supplier or the vendor for a supported update timeline.
  3. Until a fix is available, restrict access to kafka-ui to administrators on your private network or through your secure remote-access service.
  4. Review access records for unusual requests to /api/smartfilters/testexecutions and investigate unexpected changes in kafka-ui.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:LI:LA:L
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:LConfidentiality
Low
I:LIntegrity
Low
A:LAvailability
Low

Weaknesses

Affected Products

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

and 1 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-5562 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store