CVE-2025-27818 is a high-severity deserialization vulnerability in Apache Kafka, affecting versions since 2.0.0 (Kafka Connect 2.3.0). An authenticated operator with specific permissions can exploit this by manipulating the sasl.jaas.config property in Kafka Connect, forcing the server to connect to an attacker-controlled LDAP server. This allows for the deserialization of untrusted data, potentially leading to Remote Code Execution (RCE) if suitable gadgets are present. The attack vector is network-based with low attack complexity and requires low privileges, but can result in high impact to confidentiality, integrity, and availability. While the vulnerability has a CVSS score of 8.8 (HIGH), there is currently no evidence of active exploitation, public exploit code, or significant community discussion. Mitigations include disabling problematic login modules, validating connector configurations, and implementing custom client override policies.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.0, < 3.9.1CPE matchmatch criteria | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* | ||
>= 2.3.0, <= 3.9.0CPE match | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.