Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 26 Feb 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aiven
Aiven klaw |
|
| CPEs | cpe:2.3:a:aiven:klaw:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aiven
Aiven klaw |
Thu, 12 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Aiven-open
Aiven-open klaw |
|
| Vendors & Products |
Aiven-open
Aiven-open klaw |
Wed, 11 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2. | |
| Title | Klaw has an improper authorisation check on /resetMemoryCache | |
| Weaknesses | CWE-285 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-12T21:21:30.163Z
Reserved: 2026-02-09T17:41:55.859Z
Link: CVE-2026-25999
Updated: 2026-02-12T21:21:27.263Z
Status : Analyzed
Published: 2026-02-11T21:16:20.963
Modified: 2026-02-26T23:25:10.173
Link: CVE-2026-25999
No data.
OpenCVE Enrichment
Updated: 2026-04-18T12:45:45Z