{"id":"CVE-2026-25999","summary":"Klaw has an improper authorisation check on /resetMemoryCache","details":"Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2.","aliases":["GHSA-rp26-qv9w-xr5q"],"modified":"2026-08-12T15:31:58.954963Z","published":"2026-02-11T21:00:30.271Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-285"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25999.json"},"references":[{"type":"WEB","url":"https://github.com/Aiven-Open/klaw/releases/tag/v2.10.2"},{"type":"ADVISORY","url":"https://github.com/Aiven-Open/klaw/security/advisories/GHSA-rp26-qv9w-xr5q"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25999.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25999"},{"type":"FIX","url":"https://github.com/Aiven-Open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aiven-open/klaw","events":[{"introduced":"0"},{"fixed":"b539ef5fbb96cad8892f1ed522a3a8194e1b8773"},{"fixed":"617ed96b1db111ed498d89132321bf39f486e3a1"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:aiven:klaw:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.10.2"}]}}],"versions":["v2.10.1","v2.10.0","v2.9.0","v2.8.0","v2.7.0","v.2.6.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.0","v1.2.0","v1.1.0","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25999.json","vanir_signatures_modified":"2026-08-12T15:31:58Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["306360994372993250348508872170603247308","272188010370807196142997922820141825303","8541717271924304080719792911515623369","233958640032537030238062040257025281593","324498631389457694903772077729344280567","33617773262469598814372893584857514478","152297790026614686388399696849563657784","88313166850082545840729972993415078359","285525038857477499674909472925064053925","159230446039195506135015615447488495440","100841535560209611189351669304871390073","289855470334530897388674086337131010693","181913182998811399471617383786720088589","7720319946903789588633356756329017420","324498631389457694903772077729344280567","33617773262469598814372893584857514478","90914288935725456525390391587865863637","217265189017568161780257573643218667214","45886001985857312237473451175070277315"],"threshold":0.9},"id":"CVE-2026-25999-07e9121e","signature_type":"Line","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java"}},{"deprecated":false,"digest":{"function_hash":"44734951941540807426043680462618471994","length":785},"id":"CVE-2026-25999-103a4549","signature_type":"Function","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/main/java/io/aiven/klaw/config/ConfigUtils.java","function":"applyHttpSecurityConfig"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/main/java/io/aiven/klaw/controller/UtilController.java","function":"resetMemoryCache"},"deprecated":false,"digest":{"function_hash":"313834179744190395871066788150399690085","length":153},"id":"CVE-2026-25999-1775b5e9"},{"deprecated":false,"digest":{"function_hash":"214032340629346672530865034647164446677","length":489},"id":"CVE-2026-25999-215a6e43","signature_type":"Function","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java","function":"resetCacheNotAuthorized"}},{"source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/main/java/io/aiven/klaw/config/ConfigUtils.java"},"deprecated":false,"digest":{"line_hashes":["156026122269467503163070331386697968187","309264451252014547816192856011183838891","253064676035050233502481827058723296850","93877037460188463246620709211379517946"],"threshold":0.9},"id":"CVE-2026-25999-312d5472","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/main/java/io/aiven/klaw/config/SecurityConfigNoSSO.java","function":"securityFilterChain"},"deprecated":false,"digest":{"function_hash":"24806314133742703021338972960783144467","length":729},"id":"CVE-2026-25999-3efa305d","signature_type":"Function"},{"source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/main/java/io/aiven/klaw/service/CommonUtilsService.java","function":"resetCacheOnOtherServers"},"deprecated":false,"digest":{"function_hash":"53111505576804944119101155227571494044","length":1172},"id":"CVE-2026-25999-9aa8a2ae","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"line_hashes":["81646998477010980065201713771676341268","274835296542859760672098211872654301077","146602497720127959898095754172648200157","308513204831544866027462239433130106953"],"threshold":0.9},"id":"CVE-2026-25999-a1af9d24","signature_type":"Line","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/test/java/io/aiven/klaw/controller/UtilControllerTest.java"}},{"target":{"file":"core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java","function":"resetCache"},"deprecated":false,"digest":{"function_hash":"236788014738034644361663338913053291793","length":494},"id":"CVE-2026-25999-a643d015","signature_type":"Function","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1"},{"signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/main/java/io/aiven/klaw/service/UtilControllerService.java"},"deprecated":false,"digest":{"line_hashes":["8846973360033805104168374443171843367","150886369171488159095828364504009662508","79768399169145896163023104680110404699","10308205867892243475088511067146382695","183614578332110173882044695881927027200","222400066869717482109860611654544895107","306754607248161284828894675872003300387","293093664154561992078625558302813022687","290743621553371954505824600234057542120","260632946064575964000112816163498421755","14323386008413301357675620395388627311","330872959141000422353897486204357076556","189418979708453670273797564419113964304","115430052770519857387797495003999597263","334160917734341215241841557382923977650"],"threshold":0.9},"id":"CVE-2026-25999-abf0f422","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"253006144826224051806916233302593443267","length":578},"id":"CVE-2026-25999-b2634f0e","signature_type":"Function","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/test/java/io/aiven/klaw/controller/UtilControllerTest.java","function":"resetMemoryCache"}},{"target":{"file":"core/src/main/java/io/aiven/klaw/controller/UtilController.java"},"deprecated":false,"digest":{"line_hashes":["172764066385864110329207165123921632855","283047025814250871328651879289866235508","118993911031398220284839641039900453933","124378780084258849121530106918359121687","141488861446761744045181569738661580424"],"threshold":0.9},"id":"CVE-2026-25999-ba8e436b","signature_type":"Line","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1"},{"deprecated":false,"digest":{"line_hashes":["256356884060256588572479991904544443946","309264451252014547816192856011183838891","253064676035050233502481827058723296850","93877037460188463246620709211379517946"],"threshold":0.9},"id":"CVE-2026-25999-d9c520d3","signature_type":"Line","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/main/java/io/aiven/klaw/config/SecurityConfigNoSSO.java"}},{"target":{"file":"core/src/main/java/io/aiven/klaw/service/CommonUtilsService.java"},"deprecated":false,"digest":{"line_hashes":["149043346349386900350596171146926898344","305196801733851080171159703035568650657","291534471190434544062245874435619326526","235949530631845871284923785043328329931","12380007417898230167988394222700105481","280035799344897145618786560612887697319","30906907383647841107098686640983733612","188791098435045362714792953725126828593","61635538685353906829264813379471894262","183715301753375707755859985423065446629","271017760794813228801352012253533522108","3223044092683766641471921419030812749","328059891077179253171240288906584838346","224825255235788066277371365723186643133","225069206786098658300259559941888185010","12518487481621241087442389340482640433","268719877561396383709800055850613839037","150816921098026913299392422367166946458","136091316497007154848271275781826386977","198780663636917681950560501784817671463","306217201210717995520845973416476150075","316688794651432597889378722832050110843","183770182732360835127818722381800422506","19187863245970342284614982175243545747"],"threshold":0.9},"id":"CVE-2026-25999-ec906b8e","signature_type":"Line","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1","target":{"file":"core/src/main/java/io/aiven/klaw/service/UtilControllerService.java","function":"resetCache"},"deprecated":false,"digest":{"function_hash":"237569681829982812714397495743267487972","length":963},"id":"CVE-2026-25999-ef677929"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H"}]}