Skip to main content
HIGH

CVE-2025-27818

Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration

CVSS v3

8.8

HIGH

EPSS Score

1.0 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

none

SSVC status

Description

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka clusters since Apache Kafka 2.0.0 (Kafka Connect 2.3.0). When configuring the broker via config file or AlterConfig command, or connector via the Kafka Kafka Connect REST API

Technical details

Published
2025-06-10
Last Modified
2025-07-11

Frequently asked questions

What is CVE-2025-27818?

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka clusters since Apache Kafka 2.0.0 (Kafka Connect 2.3.0). When configuring the broker via config file or AlterConfig command, or connector via the Kafka Kafka Connect REST API

Is CVE-2025-27818 actively exploited?

Active exploitation of CVE-2025-27818 has not been confirmed. Its EPSS score was 1.0% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2025-27818?

CVE-2025-27818 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2025-27818 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key