CVE-2026-15911

Summary

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

Affected Software

VendorProductVersion RangeStatus
confluentconfluent-kafka0 <= 2.14.2affected

Weaknesses

  • CWE-295: CWE-295 Improper certificate validation

References