VORANT. Threat Intelligence Sign in Get the full feed

Apache Kafka versions 4.x before 4.3.0 contain a vulnerability allowing attackers to…

high vulnerability

Apache Kafka versions 4.x before 4.3.0 contain a vulnerability allowing attackers to bypass security policies and access confidential data.

The French CERT has published an advisory regarding a security vulnerability in Apache Kafka. The flaw affects all 4.x versions prior to 4.3.0 and enables attackers to circumvent security policies and compromise data confidentiality.

The vulnerability is tracked as CVE-2026-41115 and was disclosed on June 2, 2026. Apache has released version 4.3.0 to address this issue. Organizations running affected versions should consult the official Apache Kafka security bulletin for patching guidance.

Given Kafka's widespread use as a distributed streaming platform in enterprise environments, this vulnerability poses significant risk to organizations that rely on it for handling sensitive data streams and event processing.

Mentioned in this report

Vulnerabilities CVE-2026-41115

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0678

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free