/Vulnerability Library

Provectus kafka-ui <=0.7.2 - Remote Code Execution

CVE-2026-5562
Verified

Description

Provectus kafka-ui versions 0.7.0 through 0.7.2 are vulnerable to code injection in the `/api/smartfilters/testexecutions` endpoint. The `filterCode` parameter is evaluated as a Groovy expression without sandboxing, allowing an unauthenticated attacker to execute arbitrary code and operating-system commands on the host.

Severity

Critical

CVSS Score

9.8

Exploit Probability

3%

Affected Product

kafka-ui

Published Date

September 10, 2026

Template Author

christianfl, 0xnayel

CVE-2026-5562.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-5562
CWE ID:
cwe-94

References

https://nvd.nist.gov/vuln/detail/CVE-2026-5562https://vuldb.com/?id.355332https://github.com/provectus/kafka-ui

Remediation Steps

Provectus kafka-ui is end-of-life and no patched release exists (0.7.2 is the final version). Migrate to the maintained kafbat/kafka-ui fork, and in the meantime restrict network access to the interface and place it behind authentication.