Junglewise Threat Intelligence

CVE-2026-76403: Splunk Connect for Kafka improper certificate validation in Kerberos authentication

CVE-2026-76403 · Severity: high · CVSS 7.4 · Published 2026-08-19

Technologies: Splunk Connect For Kafka. Vendors: Splunk.

Executive brief

Splunk Connect for Kafka is a connector that ships data from Apache Kafka to Splunk Enterprise for analysis. An attacker positioned on the network path between Kafka and Splunk can intercept, read, or modify all data in transit when Kerberos authentication is combined with HTTP Event Collector, because certificate validation is bypassed in this authentication flow. This could expose sensitive business data or allow tampering with log records used for compliance and investigation.

Technical details

The vulnerability is an improper certificate validation flaw (CWE-295) in the Kerberos authentication path of Splunk Connect for Kafka versions below 2.2.7. When configuring Kerberos authentication with HTTP Event Collector, the connector fails to apply configured certificate validation options when building the HTTP client, leaving the connection susceptible to man-in-the-middle (MITM) attacks. An attacker positioned on the network path can intercept and decrypt HTTPS traffic, or inject malicious content without detection. The attack requires network proximity to the data path but no authentication credentials. The vulnerability was fixed in version 2.2.7.

Affected products

  • Splunk Connect for Kafka below 2.2.7

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 2.2.7

References

Related threats