{"id":"GHSA-r427-j2h7-wv3m","summary":"Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator","details":"### Impact\n\nWhen only the Topic or only the User operators are deployed as part of the Entity Operator in the `Kafka` custom resource, the RBAC rights are not following the principle of least-privilege and the Entity Operator ServiceAccount still has access rights corresponding to both operators. That might allow the ServiceAccount to access `KafkaUser` custom resources and Secrets when the User operator is not deployed and access `KafkaTopic` custom resources when the Topic operator is not deployed.\n\n### Patches\n\nThe issue is fixed in Strimzi 1.0.1 and 1.1.0.\n\n### Workarounds\n\nThere is no workaround for this issue.","aliases":["CVE-2026-55226"],"modified":"2026-06-18T13:26:31.032797Z","published":"2026-06-18T13:04:49Z","database_specific":{"cwe_ids":["CWE-269","CWE-272"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-18T13:04:49Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/strimzi/strimzi-kafka-operator/security/advisories/GHSA-r427-j2h7-wv3m"},{"type":"PACKAGE","url":"https://github.com/strimzi/strimzi-kafka-operator"}],"affected":[{"package":{"name":"io.strimzi:strimzi","ecosystem":"Maven","purl":"pkg:maven/io.strimzi/strimzi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.1"}]}],"versions":["0.10.0","0.11.0","0.11.1","0.11.2","0.11.3","0.11.4","0.12.0","0.12.1","0.12.2","0.13.0","0.14.0","0.15.0","0.16.0","0.16.1","0.16.2","0.17.0","0.18.0","0.19.0","0.20.0","0.20.1","0.21.0","0.21.1","0.22.0","0.22.1","0.23.0","0.24.0","0.25.0","0.26.0","0.26.1","0.27.0","0.27.1","0.28.0","0.29.0","0.30.0","0.31.0","0.31.1","0.32.0","0.33.0","0.33.1","0.33.2","0.34.0","0.35.0","0.35.1","0.36.0","0.36.1","0.37.0","0.38.0","0.39.0","0.40.0","0.41.0","0.42.0","0.43.0","0.44.0","0.45.0","0.45.1","0.45.1-RC1","0.45.2","0.45.2-RC1","0.46.0","0.46.1","0.46.1-RC1","0.47.0","0.47.0-RC1","0.48.0","0.48.0-RC1","0.49.0","0.49.0-RC1","0.49.0-RC2","0.49.1","0.49.1-RC1","0.50.0","0.50.0-RC1","0.50.1","0.50.1-RC1","0.51.0","0.51.0-RC1","0.51.0-RC2","0.9.0","1.0.0","1.0.0-RC1","1.0.0-RC2"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-r427-j2h7-wv3m/GHSA-r427-j2h7-wv3m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N"}]}