Impact
In Splunk Connect for Kafka versions older than 2.2.7, an unauthenticated user on the network path can read or alter all data sent from the connector because the Kerberos authentication path does not apply the configured certificate validation options when the HTTP client is built. This flaw permits attackers to intercept, modify, or inject traffic that the collector sends through the HTTP Event Collector in Splunk Enterprise, resulting in a compromise of both confidentiality and integrity of the forwarded events.
Affected Systems
The vulnerability affects Splunk Connect for Kafka deployments on Splunk Enterprise. All installations running any version below 2.2.7 are susceptible, regardless of the environment, because the flaw is present in the core connector code and not mitigated by later configuration or external security controls.
Risk and Exploitability
The flaw carries a CVSS score of 7.4, indicating a high impact if exploited. EPSS data is not available, so the current exploitation probability cannot be quantified, but the vulnerability is not listed in CISA KEV, suggesting no known publicly distributed exploits at this time. The likely attack vector is an unauthenticated actor on the internal network who can reach the HTTP Event Collector endpoint; the attacker does not need special credentials, only network access. Since the Kerberos path bypasses certificate validation, the attacker can manipulate or eavesdrop on the traffic before it reaches Splunk.
OpenCVE Enrichment