CVE-2026-76258
Received Received - Intake

Arbitrary URL Forwarding in Splunk Secure Gateway

Vulnerability report for CVE-2026-76258, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and cause Splunk Secure Gateway to forward mobile user requests, including tokens that compromise all relevant data available to the affected mobile user, to an attacker-controlled Uniform Resource Locator (URL). The vulnerability is possible because a hard-coded cryptographic key in the Splunk Secure Gateway companion app registration handler allows for arbitrary callback URL registration without restriction. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
splunk splunk_enterprise to 9.4.14 (exc)
splunk splunk_secure_gateway to 3.8.71 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise and Splunk Secure Gateway. A non-admin user can register a malicious companion app due to a hard-coded cryptographic key. This allows the app to forward mobile user requests, including authentication tokens, to an attacker-controlled URL, potentially exposing sensitive data.

Impact Analysis

If exploited, this vulnerability could allow attackers to steal authentication tokens and access sensitive data available to mobile users. This may lead to unauthorized data exposure or further attacks on the Splunk environment.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA compliance. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches.

Mitigation Strategies

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14 and Splunk Secure Gateway to versions 3.10.10, 3.9.24, or 3.8.71 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76258. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart