PT-2026-78827 · Splunk · Splunk Connect For Kafka+1
CVE-2026-76400
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Connect for Kafka versions prior to 2.2.7
Description
An unauthenticated user can cause the connector to retry failed event batches indefinitely until event delivery stops. This occurs when the user can reach the Kafka Connect REST API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise. The issue stems from the HTTP Event Collector delivery retry handling using an unbounded default for failed batches instead of a finite retry limit.
Recommendations
Update to version 2.2.7 or later.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Connect For Kafka
Splunk Enterprise