Splunk Connect for Kafka是美国Splunk公司的一款将Kafka数据接入分析平台的连接器。 Splunk Connect for Kafka 2.2.7之前版本存在加密问题漏洞,该漏洞源于Kerberos认证路径在构建HTTP客户端时未应用配置的证书验证选项,可能导致未经身份验证的用户读取或修改从连接器发送的所有相关数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk Connect for Kafka | 2.2< 2.2.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk Connect for Kafka | 2.2 ~ 2.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76311 | 9.4 CRITICAL | Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise |
| CVE-2026-76310 | 9.4 CRITICAL | Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise |
| CVE-2026-76312 | 9.4 CRITICAL | Improper Access Control through Embedded Reports in Splunk Enterprise |
| CVE-2026-76404 | 9.1 CRITICAL | Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server |
| CVE-2026-76335 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76395 | 8.8 HIGH | Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading |
| CVE-2026-76316 | 8.8 HIGH | Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise |
| CVE-2026-76253 | 8.8 HIGH | Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterpr |
| CVE-2026-76352 | 8.8 HIGH | Improper Authorization through the REST API in Splunk Enterprise |
| CVE-2026-76315 | 8.8 HIGH | Code Injection through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76319 | 8.8 HIGH | Remote Code Execution (RCE) through Federated Search in Splunk Enterprise |
| CVE-2026-76313 | 8.8 HIGH | Remote Code Execution (RCE) through the REST API in Splunk Enterprise |
| CVE-2026-76351 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secu |
| CVE-2026-76317 | 8.8 HIGH | Path Traversal through the Lookup Configuration REST API in Splunk Enterprise |
| CVE-2026-76389 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for En |
| CVE-2026-76259 | 8.8 HIGH | Improper Privilege Management on the Management Port in Splunk Enterprise for Windows |
| CVE-2026-76350 | 8.8 HIGH | Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk En |
| CVE-2026-76314 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76394 | 8.3 HIGH | Missing Authorization in Container and Connection Management through the REST API in Splun |
| CVE-2026-76391 | 8.3 HIGH | Improper Privilege Management through Agent Run History in Splunk AI Toolkit |
Showing top 20 of 110 CVEs. View all on vendor page → →
No comments yet