Apache Kafka OAUTHBEARER authentication bypass, no CVE assigned yet, 8.1 rating 🔥
The vulnerability is a missing 'exp' enforcement in the SASL/OAUTHBEARER unauthenticated token acceptance path on the broker side. An attacker holding any historical Kafka session JWT can replay it indefinitely after the JWT's own 'exp' has passed.
Search at Netlas.io:
👉 Link: https://nt.ls/TQzt7
👉 Dork: http.title:"kafka" OR http.title:"Apache Kafka" OR http.body:"kafka" OR http.body:"Apache Kafka"
Read more:
https://seclists.org/oss-sec/2026/q3/18
Post #592
586

- 🔥 4
- ❤ 3
- 👾 3