ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-5562
A vulnerability was identified in provectus kafka-ui up to 0.7.2.

A vulnerability was identified in provectus kafka-ui up to 0.7.2. This impacts the function validateAccess of the file /api/smartfilters/testexecutions of the component Endpoint. The manipulation leads to code injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.52% PoC
  • provectus ui
CVE-2023-52251
Remote code execution in Provectus kafka-ui 0.4.0-0.7.2

Provectus kafka-ui versions 0.4.0 through 0.7.2 contain a code injection flaw (CWE-94) that allows arbitrary code execution via the q parameter of the /api/clusters/local/topics/{topic}/messages API endpoint. An attacker sends a crafted q value to that endpoint and the injected code executes under the privileges of the kafka-ui process on the server hosting it, potentially exposing Kafka cluster data and providing a foothold in the hosting environment. The CVSS vector requires low privileges, meaning instances with authentication enabled need valid credentials, while deployments without authentication are exposed to anyone who can reach the API. Every deployment running kafka-ui 0.4.0 through 0.7.2 is affected, and there is no fixed release because the project has had no commit since 2024-04-08. There is one public proof-of-concept and no confirmed in-the-wild exploitation or KEV listing yet, but the very high EPSS score (86.8%, 100th percentile) signals a strong likelihood of exploitation attempts within 30 days.

Do: There is no patched release, so treat all kafka-ui 0.4.0-0.7.2 instances as vulnerable: restrict network access to the kafka-ui API (allow only trusted networks and authenticated users), and review access logs for requests to /api/clusters/local/topics/*/messages containing a q parameter that could indicate probing or compromise. Watch the project repository for a fix and, because it has been inactive since April 2024, evaluate maintained forks or alternative UIs if no patch appears. Given the 86.8% EPSS probability of exploitation in the next 30 days, prioritize containment of any internet-exposed instance.

8.887% PoC
  • provectus kafka-ui 0.4.0 through 0.7.2 (inclusive); no fixed release available
moderatelikely thousands to low tens of thousands of self-hosted instances (rough estimate; no authoritative install-count data available)