PT-2026-78830 · Splunk · Splunk Connect For Kafka+1

·

CVE-2026-76403

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Splunk Connect for Kafka versions prior to 2.2.7
Description An unauthenticated user positioned in the network path can read or modify data sent from the connector when Kerberos authentication is used with the Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. This occurs because the Kerberos authentication path fails to apply the configured certificate validation options during the construction of the HTTP client.
Recommendations Update Splunk Connect for Kafka to version 2.2.7 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76403

Affected Products

Splunk Connect For Kafka
Splunk Enterprise