Unauthorized Configuration Vulnerability in Splunk Connect for Kafka
CVE-2026-76402
8.2HIGH
What is CVE-2026-76402?
In versions of Splunk Connect for Kafka prior to 2.2.7, an unauthenticated individual can access the Kafka Connect REST API, allowing them to improperly configure a non-secure HTTP Event Collector endpoint. This misconfiguration can lead to the transmission of authentication credentials to a malicious server, posing significant risks of credential exposure and unauthorized alterations in event delivery. This vulnerability arises from the default lack of secure transport validation for the HTTP Event Collector endpoint, potentially allowing attackers to intercept sensitive data sent through the connector.
Affected Version(s)
Splunk Connect for Kafka 2.2 < 2.2.7