Confluent Kafka Python Client Vulnerability in HashiCorp Vault Integration
CVE-2026-15911

7.4HIGH

Key Information:

Vendor

Confluent

Vendor
CVE Published:
1 October 2026

What is CVE-2026-15911?

The Confluent Kafka Python client's integration with HashiCorp Vault KMS is susceptible to a vulnerability that may enable remote attackers to retrieve sensitive information. This issue arises from improper validation of TLS certificates, which is not enforced by default, thereby potentially exposing data to interception or unauthorized access. It is crucial for users to promptly review their configurations and apply available patches to mitigate this risk.

Affected Version(s)

confluent-kafka 0 <= 2.14.2

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rahul Karne
.