AUGUST 26, 2026
Live Feed
Back to database
Case File

CVE-2026-76403

HIGH · CVSS 7.4 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-08-25

CyberRota Analysis

AI-Generated

Splunk Connect for Kafka versions prior to 2.2.7 are vulnerable to unauthorized data access and modification due to improper certificate validation during Kerberos authentication with the HTTP Event Collector in Splunk Enterprise. This flaw allows an unauthenticated user on the network path to exploit the data flow, potentially compromising sensitive information. Organizations using affected versions should prioritize patching to mitigate the risk of data breaches and ensure secure data transmission.

CVE
CVE-2026-76403
Severity
HIGH
CVSS
7.4
EPSS
0.19%

Original NVD Description

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because the Kerberos authentication path does not apply the configured certificate validation options when it builds the HTTP client. For more information see Install Splunk Connect for Kafka (https://help.splunk.com/en/data-management/integrate-data-with-add-ons/splunk-connect-for-kafka/2.2/install/install-splunk-connect-for-kafka), Security configurations for Splunk Connect for Kafka (https://help.splunk.com/en/splunk-enterprise/get-data-in/splunk-connect-for-kafka/2.2/configure/security-configurations-for-splunk-connect-for-kafka), and Set up and use HTTP Event Collector with configuration files (https://help.splunk.com/en/splunk-enterprise/get-data-in/get-started-with-getting-data-in/9.4/get-data-with-http-event-collector/set-up-and-use-http-event-collector-with-configuration-files) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)