CVE-2026-33557
published 2026-04-20CVE-2026-33557: A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to…
PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.58%
43.9th percentile
A possible security vulnerability has been identified in Apache Kafka.
By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can generate a JWT token from any issuer with the `preferred_username` set to any user, and the broker will accept it.
We advise the Kafka users using kafka v4.1.0 or v4.1.1 to set the config `sasl.oauthbearer.jwt.validator.class` to `org.apache.kafka.common.security.oauthbearer.BrokerJwtValidator` explicitly to avoid this vulnerability. Since Kafka v4.1.2 and v4.2.0 and later, the issue is fixed and will correctly validate the JWT token.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | kafka | >= 4.1.0 < 4.1.2 | 4.1.2 |
| apache_software_foundation | apache_kafka | 4.1.0 – 4.1.1 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
ghsa·2026-04-20
CVE-2026-33557 [CRITICAL] CWE-1285 Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
A security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can generate a JWT token from any issuer with the `preferred_username` set to any user, and the broker will accept it.
Apache advises Kafka users using kafka v4.1.0 or v4.1.1 to set the config `sasl.oauthbearer.jwt.validator.class` to `org.apache.kafka.common.security.oauthbearer.BrokerJwtValidator` explicitly to avoid this vulnerability. Since Kafka v4.1.2 and v4.2.0 and later, the issue is fixed and
GHSA
GHSA-28jg-cgg7-j4wc: A possible security vulnerability has been identified in Apache Kafka
ghsa_unreviewed·2026-04-20
CVE-2026-33557 [CRITICAL] CWE-1285 GHSA-28jg-cgg7-j4wc: A possible security vulnerability has been identified in Apache Kafka
A possible security vulnerability has been identified in Apache Kafka.
By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can generate a JWT token from any issuer with the `preferred_username` set to any user, and the broker will accept it.
We advise the Kafka users using kafka v4.1.0 or v4.1.1 to set the config `sasl.oauthbearer.jwt.validator.class` to `org.apache.kafka.common.security.oauthbearer.BrokerJwtValidator` explicitly to avoid this vulnerability. Since Kafka v4.1.2 and v4.2.0 and later, the issue is fixed and will correctly validate the JWT token.
VulDB
Apache Kafka 4.1.0 JWT Token improper authentication
vuldb·2026-04-17
CVE-2026-33557 [CRITICAL] Apache Kafka 4.1.0 JWT Token improper authentication
A vulnerability identified as critical has been detected in Apache Kafka 4.1.0. The affected element is an unknown function of the component JWT Token Handler. This manipulation causes improper authentication.
This vulnerability is registered as CVE-2026-33557. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
Red Hat
kafka: Apache Kafka: Authentication bypass via improper JWT validation
vendor_redhat·2026-04-20·CVSS 9.1
CVE-2026-33557 [CRITICAL] CWE-303 kafka: Apache Kafka: Authentication bypass via improper JWT validation
kafka: Apache Kafka: Authentication bypass via improper JWT validation
A flaw was found in Apache Kafka. By default, the `sasl.oauthbearer.jwt.validator.class` property is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`, which does not validate JSON Web Token (JWT) signatures, issuers, or audiences. A remote attacker can exploit this by crafting a malicious JWT token with an arbitrary `preferred_username`, leading to an authentication bypass and unauthorized access to the Kafka broker.
Package: openshift-serverless-1/kn-ekb-dispatcher-rhel9 (OpenShift Serverless) - Not affected
Package: openshift-serverless-1/kn-ekb-receiver-rhel9 (OpenShift Serverless) - Not affected
Package: kafka-clients (Red Hat build of Apache Camel 4 for Quarkus 3) - Not affected
Packag
No detection rules found.
No public exploits indexed.
https://kafka.apache.org/cve-listhttps://lists.apache.org/thread/v57o00hm6yszdpdnvqx2ss4561yh953hhttp://www.openwall.com/lists/oss-security/2026/04/17/2https://access.redhat.com/security/cve/CVE-2026-33557https://bugzilla.redhat.com/show_bug.cgi?id=2459739https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33557.json
2026-04-20
Published