Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-92778

Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-693 Fallo del mecanismo de protección
Fecha de publicación:
16/09/2026
Última modificación:
23/09/2026

Descripción

*** Pendiente de traducción *** CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.