CVE-2026-92778

Source
https://cve.org/CVERecord?id=CVE-2026-92778
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92778.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92778
Published
2026-09-16T20:32:36Z
Modified
2026-09-18T03:48:42Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes
Details

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election scheduler, disrupting leadership across managed Kafka clusters.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-693"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92778.json"
}
References

Affected packages

Git / github.com/yahoo/cmak

Affected ranges

Type
GIT
Repo
https://github.com/yahoo/cmak
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0.6"
        },
        {
            "fixed": "3.0.0.6"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

1.*
1.2.1
1.2.2
1.2.4
1.2.5
1.2.6
1.2.7
1.2.9.11
1.2.9.12
1.2.9.13
1.2.9.14
1.3.0.4
1.3.0.7
1.3.0.8
1.3.1.6
1.3.1.8
1.3.3.0
1.3.3.1
1.3.3.11
1.3.3.13
1.3.3.14
1.3.3.15
1.3.3.16
1.3.3.17
1.3.3.18
1.3.3.22
1.3.3.23
1.3.3.4
1.3.3.5
1.3.3.6
1.3.3.7
1.3.3.8
2.*
2.0.0.0
2.0.0.1
2.0.0.2
3.*
3.0.0.0
3.0.0.1
3.0.0.2
3.0.0.3
3.0.0.4
3.0.0.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92778.json"