CVE-2026-5562
provectus kafka-ui Endpoint testexecutions validateAccess code injection
Description
A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
In plain language
AI Worth attentionkafka-ui versions up to 0.7.2 have a remotely reachable code-injection flaw; small businesses using it should limit access and seek a vendor fix.
Unauthenticated remote code injection in kafka-ui’s `/api/smartfilters/testexecutions` endpoint through the `validateAccess` function.
What to do now
- Check whether you run kafka-ui up to version 0.7.2 and whether its web interface is reachable from outside your trusted network.
- There is currently no vendor-fixed version available; contact your software supplier or the vendor for a supported update timeline.
- Until a fix is available, restrict access to kafka-ui to administrators on your private network or through your secure remote-access service.
- Review access records for unusual requests to
/api/smartfilters/testexecutionsand investigate unexpected changes in kafka-ui.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-5562 and every CVE in our database. Create a free account — no credit card required.
Create Free Account