Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-82266: Redpanda allows anyone to control admin API on port 9644

CVE-2026-82266 · published 6 days ago
Summary

Redpanda versions up to 26.2.2 open their administrative interface to the whole network and do not require a password by default. This means anyone who can reach the server can add or remove broker accounts, change cluster settings, and stop data replication. To protect your system, enable authentication for the admin API and restrict network access to trusted hosts, or upgrade to a version where the default is more secure.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
redpanda-data redpanda <= 26.2.2
Original advisory text
Redpanda Admin API Unauthenticated Superuser Access via Default Configuration
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.
Severity
9.9 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published28 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-82266 · MITRE
Monitor software like this
Free during beta