Description
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because the Kerberos authentication path does not apply the configured certificate validation options when it builds the HTTP client. For more information see Install Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/install/install-splunk-connect-for-kafka), Security configurations for Splunk Connect for Kafka (https://help.splunk.com/en/splunk-enterprise/get-data-in/splunk-connect-for-kafka/2.2/configure/security-configurations-for-splunk-connect-for-kafka), and Set up and use HTTP Event Collector with configuration files (https://help.splunk.com/en/splunk-enterprise/get-data-in/get-started-with-getting-data-in/9.4/get-data-with-http-event-collector/set-up-and-use-http-event-collector-with-configuration-files) in the Splunk documentation.
Published: 2026-08-19
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Splunk Connect for Kafka versions older than 2.2.7, an unauthenticated user on the network path can read or alter all data sent from the connector because the Kerberos authentication path does not apply the configured certificate validation options when the HTTP client is built. This flaw permits attackers to intercept, modify, or inject traffic that the collector sends through the HTTP Event Collector in Splunk Enterprise, resulting in a compromise of both confidentiality and integrity of the forwarded events.

Affected Systems

The vulnerability affects Splunk Connect for Kafka deployments on Splunk Enterprise. All installations running any version below 2.2.7 are susceptible, regardless of the environment, because the flaw is present in the core connector code and not mitigated by later configuration or external security controls.

Risk and Exploitability

The flaw carries a CVSS score of 7.4, indicating a high impact if exploited. EPSS data is not available, so the current exploitation probability cannot be quantified, but the vulnerability is not listed in CISA KEV, suggesting no known publicly distributed exploits at this time. The likely attack vector is an unauthenticated actor on the internal network who can reach the HTTP Event Collector endpoint; the attacker does not need special credentials, only network access. Since the Kerberos path bypasses certificate validation, the attacker can manipulate or eavesdrop on the traffic before it reaches Splunk.

Generated by OpenCVE AI on August 20, 2026 at 10:33 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove Splunk Connect for Kafka.


OpenCVE Recommended Actions

  • Upgrade all Splunk Connect for Kafka installations to version 2.2.7 or later, ensuring the fix for certificate validation is applied.
  • Should an immediate upgrade not be possible, disable or remove the Splunk Connect for Kafka addon from the deployment to eliminate the exposed path.
  • As an interim safeguard, block unauthenticated traffic to the HTTP Event Collector port on network firewalls and monitor logs for suspicious ingress attempts.

Generated by OpenCVE AI on August 20, 2026 at 10:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk connect For Kafka
CPEs cpe:2.3:a:splunk:connect_for_kafka:*:*:*:*:*:*:*:*
Vendors & Products Splunk connect For Kafka

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Connect For Kafka
Vendors & Products Splunk
Splunk splunk Connect For Kafka

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because the Kerberos authentication path does not apply the configured certificate validation options when it builds the HTTP client. For more information see Install Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/install/install-splunk-connect-for-kafka), Security configurations for Splunk Connect for Kafka (https://help.splunk.com/en/splunk-enterprise/get-data-in/splunk-connect-for-kafka/2.2/configure/security-configurations-for-splunk-connect-for-kafka), and Set up and use HTTP Event Collector with configuration files (https://help.splunk.com/en/splunk-enterprise/get-data-in/get-started-with-getting-data-in/9.4/get-data-with-http-event-collector/set-up-and-use-http-event-collector-with-configuration-files) in the Splunk documentation.
Title Improper Certificate Validation through HTTP Event Collector Kerberos Authentication in Splunk Connect for Kafka
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Splunk Connect For Kafka Splunk Connect For Kafka
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:26:31.304Z

Reserved: 2026-08-19T12:02:03.632Z

Link: CVE-2026-76403

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:27.043

Modified: 2026-08-24T18:46:57.453

Link: CVE-2026-76403

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-295

    Improper Certificate Validation