CVE-2026-76251
Received Received - Intake

Information Disclosure in Splunk Enterprise

Vulnerability report for CVE-2026-76251, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Splunk Observability Cloud access token stored for the app. With this access, the user could view all relevant data available to that token and make limited changes to Splunk Observability Cloud content. The vulnerability does not affect Splunk Enterprise 9.4 and 9.3 versions. The vulnerability is possible because the app's Representational State Transfer (REST) API endpoint handlers do not enforce the read_o11y_content capability before forwarding requests with the stored access token. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
splunk splunk_enterprise to 10.0.9 (exc)
splunk splunk_observability_cloud to 10.0.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9. A non-admin or non-power user can exploit the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud using a stored access token. This allows the user to view all data accessible to the token and make limited changes to Splunk Observability Cloud content. The issue occurs because the app's REST API endpoint handlers do not enforce the read_o11y_content capability before forwarding requests.

Detection Guidance

To detect this vulnerability, check Splunk Enterprise versions for affected releases (below 10.4.2, 10.2.6, or 10.0.9). Verify if non-admin or non-power users can access the Splunk App for Splunk Observability Cloud REST API endpoints. Review user roles and capabilities to ensure read_o11y_content is enforced.

Impact Analysis

If exploited, this vulnerability could allow unauthorized users to access sensitive data and make changes to Splunk Observability Cloud content. This may lead to data breaches, unauthorized modifications, or loss of control over Splunk Observability Cloud resources. Users without admin or power roles could gain elevated privileges through the stored access token.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Exposure of personal or health data could result in legal penalties, reputational damage, and loss of trust. Organizations must ensure proper access controls to maintain compliance.

Mitigation Strategies

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, or 10.0.9 or later to address the vulnerability. Ensure the Splunk App for Splunk Observability Cloud is updated and verify that only admin or power role users can access the relevant REST API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76251. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart