Confluent Kafka Python Client Vulnerability in HashiCorp Vault Integration
CVE-2026-15911
7.4HIGH
What is CVE-2026-15911?
The Confluent Kafka Python client's integration with HashiCorp Vault KMS is susceptible to a vulnerability that may enable remote attackers to retrieve sensitive information. This issue arises from improper validation of TLS certificates, which is not enforced by default, thereby potentially exposing data to interception or unauthorized access. It is crucial for users to promptly review their configurations and apply available patches to mitigate this risk.
Affected Version(s)
confluent-kafka 0 <= 2.14.2
