Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-41115

Apache Kafka: CONSUMER_GROUP_DESCRIBE authorization differs from the documentation

Technology

Apache Kafka

CVSS Score

4.3 / 10.0

Affected Versions

4.0.0 to 4.3.0

Upstream Fix

No code change; documentation and KIP-848 corrected

Published

June 2, 2026

OSSeva Coverage

Fixed upstream

Description

The CONSUMER_GROUP_DESCRIBE (69) API checks the DESCRIBE operation on the GROUP resource, while the Kafka documentation and KIP-848 said it checked READ. ACLs written to the documentation could grant READ to users who should not join or sync groups, or leave users with DESCRIBE able to read group metadata. Kafka decided the implementation is correct and updated the documentation instead, and advises users of 4.0.0 to 4.3.0 to review group ACLs.

Upstream record: NVD · CVE.org

Is your Apache Kafka deployment affected?

If you're running 4.0.0 to 4.3.0, you need this patch. Book a discovery call to get covered.