{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/redpanda--26.2.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redpanda:redpanda:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-82266"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Redpanda (\u003c= 26.2.2)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","api-security"],"_cs_type":"advisory","_cs_vendors":["Redpanda"],"content_html":"\u003cp\u003eRedpanda versions 26.2.2 and earlier contain a critical configuration vulnerability where the Admin API is bound to 0.0.0.0:9644 by default, and the \u003ccode\u003eadmin_api_require_auth\u003c/code\u003e setting defaults to false. This configuration treats all incoming requests as having superuser privileges. An unauthenticated attacker with network access to the management port can perform sensitive operations, including the creation or deletion of broker accounts, modification of cluster-wide configurations, and the disruption of partition replication. This effectively grants an attacker full administrative control over the Redpanda cluster. Because this is a default behavior in older versions, any cluster exposed to the internet or an untrusted network segment without additional firewall controls is at risk of complete compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an attacker full administrative access to the Redpanda cluster. Observed impacts include unauthorized manipulation of cluster state, credential theft or modification of service accounts, and catastrophic data disruption through partition manipulation or service shutdown. This vulnerability poses a severe risk to data integrity and availability in any environment where the management API is reachable from outside a strictly controlled local segment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict network access to port 9644 to only known, trusted administrative IP addresses using host-based firewalls or network security groups.\u003c/li\u003e\n\u003cli\u003eUpgrade all Redpanda deployments to a version greater than 26.2.2 where the default configuration requires authentication.\u003c/li\u003e\n\u003cli\u003eReview cluster configuration files to verify that \u003ccode\u003eadmin_api_require_auth\u003c/code\u003e is explicitly set to true.\u003c/li\u003e\n\u003cli\u003eAudit logs for the Admin API to identify any unauthorized requests originating from unexpected IP addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-28T21:35:09Z","date_published":"2026-08-28T21:35:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-redpanda-admin-api/","summary":"Redpanda versions 26.2.2 and earlier insecurely expose the Admin API on port 9644 by default without authentication enabled, allowing remote attackers to perform superuser actions.","title":"CVE-2026-82266: Unauthenticated Redpanda Admin API Access","url":"https://feed.craftedsignal.io/briefs/2026-08-redpanda-admin-api/"}],"language":"en","title":"CraftedSignal Threat Feed - Redpanda (\u003c= 26.2.2)","version":"https://jsonfeed.org/version/1.1"}