CVE Feed

    Dashboard / CVE / CVE-2026-25999

    CVE-2026-25999

    Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2.

    Published:Feb 11, 2026
    Last Modified:Apr 18, 2026
    EPS:Feb 11, 2026
    EPSS Score:0.00038
    CVSS Score:7.1

    Affected Products

    Vendor
    Aiven
    Product
    Klaw
    Vendor
    Aiven-open
    Product
    Klaw

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High