OVERVIEW CVE-2026-33557 is an authentication bypass vulnerability in Apache Kafka that affects versions 4.1.0 and 4.1.1. The default JWT validator does not properly validate JWT token signatures, issuers, or audiences, allowing unauthenticated attackers to forge authentication tokens as arbitrary users. An attacker can generate a fraudulent JWT token with any issuer and set the preferred_username field to any valid user account, which the broker will accept without verification. SEVERITY This vulnerability carries a CVSS 3.1 score of 9.1 (CRITICAL) with a network-based attack vector requiring no authentication or user interaction. The attack has low complexity and requires minimal attacker resources. The impact is severe, providing high confidentiality and integrity compromise by allowing complete authentication bypass and potential unauthorized access to Kafka brokers and their data. The vulnerability does not directly impact availability. EXPLOITATION STATUS No evidence of active exploitation has been identified, as this CVE is not listed on the CISA KEV catalog and remains inactive on threat intelligence hot lists. The EPSS probability score of 0.00125 indicates this vulnerability is not currently being exploited in the wild. However, the critical severity rating and straightforward attack methodology suggest organizations should prioritize remediation through upgrading to Kafka version 4.1.2, 4.2.0, or later, or by explicitly configuring the BrokerJwtValidator class for affected versions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1.0, < 4.1.2CPE matchmatch criteria | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* | ||
>= 4.1.0, <= 4.1.1CPE match | cpe:2.3:a:apache:kafka:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.