CVE-2026-92778 MEDIUM

CVE-2026-92778: CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes

Vendor Yahoo
Product CMAK
Weakness CWE-693
Published September 16, 2026
Last update September 17, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

Key dates

02Disclosure timeline

September 16, 2026 CVE published
September 17, 2026 Record updated