CVE-2026-78166 | provectus kafka-ui up to 0.7.2 Groovy Code MessagesController.java executeSmartFilterTest code injection (Issue 4567)
A vulnerability was found in provectus kafka-ui up to 0.7.2. It has been declared as critical. The affected element is the function executeSmartFilterTest of the file kafka-ui-api/src/main/java/com/provectus/kafka/ui/controller/MessagesController.java of the component Groovy Code Handler. The manipulation results in code injection.
This vulnerability is cataloged as CVE-2026-78166. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More