Race condition in Apache Kafka - CVE-2026-35554

 

Race condition in Apache Kafka - CVE-2026-35554

Published: May 21, 2026


Vulnerability identifier: #VU132004
CSH Severity: High
CVSS v4: 7 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N]
CVE-ID: CVE-2026-35554
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. A remote attacker can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.


Affected software

Apache Kafka
WebSphere Automation
IBM Sterling B2B Integrator
Bitbucket Data Center
IBM Business Automation Workflow
Red Hat build of Quarkus
IBM Sterling File Gateway
IBM Qradar SIEM
IBM InfoSphere Information Server
IBM Disconnected Log Collector
Red Hat Camel for Spring Boot
IBM FileNet Content Manager

How to mitigate CVE-2026-35554

Install updates from vendor's website.

Apache Kafka - addressed in versions 3.9.2, 4.0.2, 4.1.2, 4.2.0
WebSphere Automation - update to 1.12.1
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.1
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
Bitbucket Data Center - update to 9.4.22
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
IBM Disconnected Log Collector - update to 2.0.1
Red Hat build of Quarkus - update to 3.27.3.SP1
Red Hat Camel for Spring Boot - update to 4.14
IBM FileNet Content Manager - addressed in versions 5.5.12.0 IF008, 5.6.0.0 IF007, 5.7.0.0 IF004

External References

Related Security Bulletins