Description
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/Aiven-Open/klaw/security/advisories/GHSA-rp26-qv9w-xr5q
Patch x_refsource_misc
https://github.com/Aiven-Open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1
Release Notes x_refsource_misc
https://github.com/Aiven-Open/klaw/releases/tag/v2.10.2
Scores
CVSS v3
7.1
EPSS
0.0027
EPSS Percentile
17.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-285
Status
published
Products (1)
aiven/klaw
< 2.10.2
Published
Feb 11, 2026
Tracked Since
Feb 18, 2026