CVE-2026-41115
Apache Kafka: CONSUMER_GROUP_DESCRIBE authorization differs from the documentation
Technology
Apache Kafka
CVSS Score
4.3 / 10.0
Affected Versions
4.0.0 to 4.3.0
Upstream Fix
No code change; documentation and KIP-848 corrected
Published
June 2, 2026
OSSeva Coverage
Fixed upstream
Description
The CONSUMER_GROUP_DESCRIBE (69) API checks the DESCRIBE operation on the GROUP resource, while the Kafka documentation and KIP-848 said it checked READ. ACLs written to the documentation could grant READ to users who should not join or sync groups, or leave users with DESCRIBE able to read group metadata. Kafka decided the implementation is correct and updated the documentation instead, and advises users of 4.0.0 to 4.3.0 to review group ACLs.
Is your Apache Kafka deployment affected?
If you're running 4.0.0 to 4.3.0, you need this patch. Book a discovery call to get covered.