Unrated severityNVD Advisory· Published Feb 11, 2026· Updated Feb 12, 2026
Klaw has an improper authorisation check on /resetMemoryCache
CVE-2026-25999
Description
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2.
Affected products
2- Aiven-Open/klawv5Range: < 2.10.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/Aiven-Open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1mitrex_refsource_MISC
- github.com/Aiven-Open/klaw/releases/tag/v2.10.2mitrex_refsource_MISC
- github.com/Aiven-Open/klaw/security/advisories/GHSA-rp26-qv9w-xr5qmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.