Remote code execution vulnerability in Splunk Connect for Kafka by Splunk
CVE-2026-76401
5.9MEDIUM
What is CVE-2026-76401?
An unauthenticated user with access to the Kafka Connect REST API in Splunk Connect for Kafka versions prior to 2.2.7 can exploit a flaw in timestamp extraction. This allows the user to submit crafted regular expressions that can cause a Kafka Connect worker thread to hang, thereby disrupting event delivery for the affected connector. The issue arises from the lack of time constraints in evaluating user-supplied regular expressions, presenting a significant risk to the operation of Kafka connectors.
Affected Version(s)
Splunk Connect for Kafka 2.2 < 2.2.7