CVE-2026-33557Disclosure(apache / kafka)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache kafka systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can generate a JWT token from any issuer with the `preferred_username` set to any user, and the broker will accept it. We advise the Kafka users using kafka v4.1.0 or v4.1.1 to set the config `sasl.oauthbearer.jwt.validator.class` to `org.apache.kafka.common.security.oauthbearer.BrokerJwtValidator` explicitly to avoid this vulnerability. Since Kafka v4.1.2 and v4.2.0 and later, the issue is fixed and will correctly validate the JWT token.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1285CWE-303

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kafka

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-04-19); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
kafka

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-04-17: 1Mentions · 2026-04-19: 2Mentions · 2026-04-20: 1Mentions · 2026-04-21: 2Mentions · 2026-04-25: 1Mentions · 2026-07-11: 1Mentions · 2026-07-13: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-19: 2Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 2Technical Details · 2026-04-25: 1Technical Details · 2026-07-11: 1Technical Details · 2026-07-13: 104-1704-1904-2004-2104-2507-1107-13
Signal classification3 categories
Disclosure
555.6%
Patch
333.3%
General
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-171
General1
2026-04-192
Disclosure1Patch1
2026-04-201
Patch1
2026-04-212
Disclosure2
2026-04-251
Patch1
2026-07-111
Disclosure1
2026-07-131
Disclosure1
Full discourse9 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-33557: Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication Critical Vulnerability Alert! Kafka is affected by CVE-2026-33557. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-33557 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-33557" Search Dork: app="Kafka" Exposure: 9k instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJLYWZrYSI=&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260713 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet announces CVE-2026-33557—a critical missing JWT token validation flaw in Kafka’s OAUTHBEARER authentication—linking to a detailed DarkEye analysis and noting 9,000 globally exposed instances.

    01002032.8K
    12.7K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-33557, and CVE-2026-33558: Vulnerabilities in Apache Kafka, up to 9.1 rating 🔥 Two new vulnerabilities in Apache Kafka: the first allows attacker to generate their own JWT from any issuer, the second flow is the sensitive information disclosure, if the NetworkClient component is set to the DEBUG log level. 👉 https://nt.ls/M6oTa

    Post summary

    Two newly disclosed Apache Kafka vulnerabilities: one permits JWT forgery from any issuer, and the other leaks sensitive data when the NetworkClient component logs at DEBUG level.

    06044786
    7.6K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 Critical - Apache Kafka auth bypass (CVE-2026-33557) Missing JWT validation in OAUTHBEARER allows attackers to forge tokens and impersonate any user. 👉 Upgrade to 4.1.2+ or enforce proper JWT validation immediately https://t.co/cnQczZhSG9

    Post summary

    This tweet alerts to an auth bypass in Apache Kafka (CVE‑2026‑33557) caused by missing JWT validation and urges users to upgrade to 4.1.2+ or enforce JWT checks immediately.

    00060187
    237 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Apache Kafka faces a critical OAUTHBEARER bypass (CVE-2026-33557) and sensitive logging leaks. Secure your data pipelines—patch to v4.1.2 or v4.2.0 today. #ApacheKafka #CyberSecurity #InfoSec #JWT #DataSecurity #ZeroTrust #EventStreaming https://securityonline.info/apache-kafka-jwt-authentication-bypass-logging-vulnerabilities-2026/ https://t.co/mMkLsczIy8

    Post summary

    Apache Kafka CVE-2026-33557 is an OAUTHBEARER bypass with logging leaks; patching to v4.1.2 or v4.2.0 is advised.

    00021470
    12.5K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerability in #Apache Kafka. CVE-2026-33557 CVSS: 9.1. This vulnerability could be exploited to breach confidentiality and bypass security policies. #Patch #Patch #Patch

    Post summary

    The short warning labels CVE-2026-33557 as a critical flaw in Apache Kafka with a high CVSS score and potential confidentiality impact, but offers no exploit details or patch information.

    01010194
    7.2K followersView on X
  • Giuseppe `N3mes1s`@N3mes1s
    Disclosure

    @Netlas_io CVE-2026-33557: Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication ? https://www.openwall.com/lists/oss-security/2026/04/17/2

    Post summary

    The tweet points out a new CVE for Apache Kafka involving missing JWT token validation in OAUTHBEARER authentication, but provides no PoC, exploit, patch, or evidence of real‑world attacks.

    10000268
    13.4K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical vulnerability (CVE-2026-33557) in `Apache Kafka` OAUTHBEARER authentication may allow JWT bypass. Review configurations and apply patches when available. #Kafka #AuthN #InfoSec https://www.pulsepatch.io/posts/cve-2026-33557-apache-kafka-jwt-validation-bypass

    Post summary

    The post highlights a critical Apache Kafka OAUTHBEARER authentication flaw (CVE-2026-33557) that could allow JWT bypass and advises reviewing configurations and applying patches promptly.

    00001117
    12 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-33557: Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication https://www.openwall.com/lists/oss-security/2026/04/17/2 CVE-2026-33558: Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output https://www.openwall.com/lists/oss-security/2026/04/17/3

    Post summary

    Two new CVEs affecting Apache Kafka were announced, detailing a missing JWT token validation issue and information exposure via client log output.

    00000209
    4.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33557 CVE-2026-33557 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33557

    Post summary

    The post merely references CVE-2026-33557 and links to a generic vulnerability details page, providing no detailed information on exploitation, mitigation, or technical aspects.

    0000035
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachekafka---

Explore more