Race condition in Apache Kafka - CVE-2026-35554
Published: May 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. A remote attacker can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
Affected software
WebSphere Automation
IBM Sterling B2B Integrator
Bitbucket Data Center
IBM Business Automation Workflow
Red Hat build of Quarkus
IBM Sterling File Gateway
IBM Qradar SIEM
IBM InfoSphere Information Server
IBM Disconnected Log Collector
Red Hat Camel for Spring Boot
IBM FileNet Content Manager
How to mitigate CVE-2026-35554
WebSphere Automation - update to 1.12.1
IBM Sterling File Gateway - addressed in versions 6.2.1.2, 6.2.2.1
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2, 6.2.2.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
Bitbucket Data Center - update to 9.4.22
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 3
IBM Business Automation Workflow - addressed in versions 24.0.0-IF009, 24.0.1-IF008, 25.0.0-IF005, 26.0.0.0
IBM Disconnected Log Collector - update to 2.0.1
Red Hat build of Quarkus - update to 3.27.3.SP1
Red Hat Camel for Spring Boot - update to 4.14
IBM FileNet Content Manager - addressed in versions 5.5.12.0 IF008, 5.6.0.0 IF007, 5.7.0.0 IF004
External References
Related Security Bulletins
- Race condition in Apache Kafka
- IBM WebSphere Automation update for Apache Kafka
- Multiple vulnerabilities in Red Hat build of Quarkus 3.27.3
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4
- Race condition in FileNet Content Manager
- Multiple vulnerabilities in IBM Disconnected Log Collector
- Multiple vulnerabilities in Bitbucket Data Center
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Sterling B2B Integrator and IBM Sterling File Gateway
- Multiple vulnerabilities in IBM Business Automation Workflow
- Multiple vulnerabilities in IBM InfoSphere Information Server