Redpanda versions through 26.2.2 bind the Admin API to all network interfaces (0.0.0.0:9644) with authentication disabled by default, allowing any network-reachable attacker to be treated as a superuser. This enables unauthenticated creation and deletion of broker accounts, cluster configuration tampering, and disruption of partition replication, posing a critical risk to any exposed deployment.
Updated Aug 29, 2026 · CVSS 9.8