Moderate severityNVD Advisory· Published Jun 18, 2026
Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
CVE-2026-55226
Description
Impact
When only the Topic or only the User operators are deployed as part of the Entity Operator in the Kafka custom resource, the RBAC rights are not following the principle of least-privilege and the Entity Operator ServiceAccount still has access rights corresponding to both operators. That might allow the ServiceAccount to access KafkaUser custom resources and Secrets when the User operator is not deployed and access KafkaTopic custom resources when the Topic operator is not deployed.
Patches
The issue is fixed in Strimzi 1.0.1 and 1.1.0.
Workarounds
There is no workaround for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.strimzi:strimziMaven | < 1.0.1 | 1.0.1 |
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.