Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.2
CVE-2026-92751: CMAK up to 3.0.0.6 lets attackers change settings
CVE-2026-92751 · published 12 days ago
Summary
The CMAK tool (versions up to 3.0.0.6) does not block forged web requests, so a malicious site could trick a logged‑in administrator into performing actions like deleting topics or altering cluster configuration. This could happen without the admin realizing it. Apply the latest update from the vendor or add a proper request‑validation measure to stop these hidden requests.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| yahoo | cmak | <= 3.0.0.6 |
Original advisory text
CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter
CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints like topic deletion and cluster configuration changes, leveraging the operator's HTTP Basic authentication credentials or play-basic-authentication cookie without SameSite protection.
References
- https://github.com/yahoo/CMAK/issues/935
- https://github.com/yahoo/CMAK
- https://github.com/yahoo/CMAK/blob/3.0.0.6/app/loader/KafkaManagerLoader.scala#L...
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92751... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-92751 Vendor Advisory
- https://www.vulncheck.com/advisories/cmak-through-3.0.0.6-cross-site-request-for...
Severity
7.2
High
CVSS 3.1: 8.1 (MITRE)
Exploitation
EPSS <1%
Type
CWE-352Cross-Site Request Forgery (CSRF)
Timeline
Published16 Sep 2026
Updated27 Sep 2026
First seen16 Sep 2026
Track software like this
Free during beta