CVE-2026-27134Patch(linuxfoundation / strimzi_kafka_operator)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation strimzi_kafka_operator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly configures the trusted certificates for mTLS authentication on the internal as well as user-configured listeners. All CAs from the CA chain will be trusted. And users with certificates signed by any of the CAs in the chain will be able to authenticate. This issue affects only users using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs. It does not affect users using the Strimzi-managed Cluster and Clients CAs. It also does not affect users using custom Cluster or Clients CA with only a single CA (i.e., no CA chain with multiple CAs). This issue has been fixed in version 0.50.1. To workaround this issue, instead of providing the full CA chain as the custom CA, users can provide only the single CA that should be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-295CWE-296

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strimzi_kafka_operator

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-19); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
strimzi_kafka_operator

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-02-21: 1Mentions · 2026-02-22: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-22: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-21: 1Technical Details · 2026-02-22: 102-1902-2002-2102-22
Signal classification2 categories
Patch
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-191
Patch1
2026-02-201
Disclosure1
2026-02-211
Disclosure1
2026-02-221
Patch1
Full discourse4 posts
  • Strimzi@strimziio
    Patch

    We have released #Strimzi 0.50.1. This patch release addresses a few minor bug fixes and dependency updates. It also fixes two new Strimzi CVEs: CVE-2026-27133 and CVE-2026-27134! Please check the new release and the CVEs, and upgrade if needed: ➡️ https://github.com/strimzi/strimzi-kafka-operator/releases/tag/0.50.1

    Post summary

    Strimzi 0.50.1 is a patch release that fixes CVE‑2026‑27133 and CVE‑2026‑27134; users should upgrade to mitigate these vulnerabilities.

    02110299
    2.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A trust evaluation vulnerability (CVE-2026-27134) in `Strimzi Kafka Operator` allows unintended CAs in a custom chain to be trusted for mTLS user auth. Users should update. #Strimzi #Kafka #KubernetesSecurity https://www.pulsepatch.io/posts/cve-2026-27134-strimzi-kafka-operator-mtls-trust-vulnerability

    Post summary

    A trust evaluation vulnerability in Strimzi Kafka Operator allows unintended CAs to be trusted for mTLS authentication; users are advised to update to mitigate the issue.

    0000071
    1 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27134** pertains to a flaw in Strimzi, an open-source project that simplifies running Apache Kafka on Kubernetes or OpenShift. The vulnerability arises in versions **0.49.0 through 0.50.0**, where the software incorrectly configures trusted certificates for mutual TLS (mTLS) authentication when a **multistage CA chain** is used for custom Cluster or Clients CAs. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #AuthBypass #Apache https://cvetodo.com/cve/CVE-2026-27134

    Post summary

    The post announces a new CVE (CVE‑2026‑27134) affecting Strimzi 0.49.0‑0.50.0, describing an mTLS mis‑configuration that could lead to authentication bypass; no exploit, PoC, or patch is mentioned.

    0000047
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27134 Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using … https://www.cve.org/CVERecord?id=CVE-2026-27134

    Post summary

    The excerpt references CVE‑2026‑27134, noting a vulnerability in Strimzi’s Kafka deployment affecting versions 0.49.0‑0.50.0, but provides no PoC, exploit, or patch information.

    0000052
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationstrimzi_kafka_operator---

Explore more