VYPR
Medium severity5.4NVD Advisory· Published Sep 16, 2026

CVE-2026-92778

CVE-2026-92778

Description

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Yahoo/Cmakreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=3.0.0.6

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.