CVE-2026-15911
HighPublished
Confluent Kafka Python Improper TLS Certificate Validation
- Published
- Oct 1, 2026
- Updated
- Oct 1, 2026
- Assigning CNA
- ibm
- Evidence observed
- Oct 5, 2026
Primary CVSS
7.4/ 10High
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N0.2%
Low · next 30 days
- Percentile
- 9.1%
- Model date
- Oct 3, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
Sources
Disabled TLS Certificate Verification for HashiCorp Vault KMS in confluent-kafka
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.