Unauthorized Configuration Vulnerability in Splunk Connect for Kafka
CVE-2026-76402

8.2HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76402?

In versions of Splunk Connect for Kafka prior to 2.2.7, an unauthenticated individual can access the Kafka Connect REST API, allowing them to improperly configure a non-secure HTTP Event Collector endpoint. This misconfiguration can lead to the transmission of authentication credentials to a malicious server, posing significant risks of credential exposure and unauthorized alterations in event delivery. This vulnerability arises from the default lack of secure transport validation for the HTTP Event Collector endpoint, potentially allowing attackers to intercept sensitive data sent through the connector.

Affected Version(s)

Splunk Connect for Kafka 2.2 < 2.2.7

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.