Database/Control plane, storage & DevOps
Confluent Kafka Python client: TLS certificate verification disabled by default toward HashiCorp Vault KMS
Impact
The client's Vault KMS integration, used to fetch the keys that protect Kafka message payloads, did not validate the Vault server's TLS certificate by default. An attacker positioned on the path between a producer or consumer and Vault can impersonate Vault, which means capturing the Vault token the client presents and serving back key material of the attacker's choosing. Where Kafka carries telemetry, job events or feature data across a fleet, this exposes the secret that guards those payloads rather than just one message. Confluent scores it 7.4 with high confidentiality and integrity impact; the record gives no indication of exploitation in the wild.
Who can reach it
An attacker able to intercept or redirect the network path from a Kafka client process to its Vault endpoint - the same-VLAN or compromised-DNS position. No credentials on either side are needed; Confluent rates attack complexity high because the position has to be obtained first.
What to do
Upgrade the confluent-kafka Python client to the fixed release named in Confluent advisory CONFSA-2026-22 and explicitly enable TLS verification on the Vault KMS configuration. This is a library bump: redeploy and restart each producer and consumer process that uses the Vault KMS integration. No node drain or reboot is involved, but every service with the client embedded has to be rolled.
References
Related entries
- N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverCVE-2026-18556 · N-able N-centralHigh
- Jenkins TICS plugin: attacker-controlled build variables execute arbitrary commands on the build agentCVE-2026-84675 · Jenkins TICS plugin (build environment variable expansion into an OS command)High
- Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle): SUPPLY CHAIN, VERIFICATION BYPASS: keylessNCVD-2026-056-sigstore-cosign-verify-blob-veri · Sigstore cosign (verify-blob / verify-blob-attestation, legacy JSON bundle)High
- Grafana: Stored XSS via Unified AlertingCVE-2022-31097 · GrafanaHigh
- Linux i915 GVT-g mediated GPU virtualisation (debugfs teardown): Companion to the vGPU debugfs cleanup bug: GVT-gCVE-2023-54098 · Linux i915 GVT-g mediated GPU virtualisation (debugfs teardown)High
- HPE Insight Remote Support: XML external entity injection allows remote disclosure of server informationCVE-2024-11622 · HPE Insight Remote Support (XXE)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.