CVE-2026-76256
Received Received - Intake

Information Disclosure in Splunk Enterprise via REST API

Vulnerability report for CVE-2026-76256, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup Language setup and instance settings information through Splunk Secure Gateway Representational State Transfer (REST) API endpoints. The vulnerability is possible because the affected Security Assertion Markup Language setup and instance settings REST API endpoints do not enforce authorization requirements before returning configuration information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
splunk splunk_enterprise to 10.4.2 (exc)
splunk splunk_enterprise to 10.2.6 (exc)
splunk splunk_enterprise to 10.0.9 (exc)
splunk splunk_enterprise to 9.4.14 (exc)
splunk splunk_secure_gateway to 3.10.9 (exc)
splunk splunk_secure_gateway to 3.9.23 (exc)
splunk splunk_secure_gateway to 3.8.70 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise and Splunk Secure Gateway. It allows non-admin or non-power users to read sensitive SAML setup and instance settings via REST API endpoints due to missing authorization checks.

Impact Analysis

An attacker with limited access could exploit this to view confidential configuration details, potentially leading to further attacks or data exposure.

Compliance Impact

This could violate compliance by exposing sensitive data, leading to unauthorized access to security settings and potential breaches of confidentiality requirements.

Mitigation Strategies

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14, and Splunk Secure Gateway to versions 3.10.9, 3.9.23, or 3.8.70 or later to address the authorization bypass in REST API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76256. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart