CVE-2026-76261
Received
Received - Intake
Sensitive Data Exposure in Splunk Enterprise via REST API
Vulnerability report for CVE-2026-76261, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-19
Last updated on: 2026-08-19
Assigner: Cisco Systems, Inc.
Description
Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, which are secrets that compromise affected Spacebridge private-key material stored in the app collection, through the Splunk Secure Gateway App Key Value Store Representational State Transfer (REST) API. The vulnerability is possible on instances upgraded from older Splunk Secure Gateway deployments when the private-key migration remains incomplete, leaving key material in a collection with an insecure default access control list.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| splunk | splunk_enterprise | to 10.4.2 (exc) |
| splunk | splunk_enterprise | to 10.2.6 (exc) |
| splunk | splunk_enterprise | to 10.0.9 (exc) |
| splunk | splunk_enterprise | to 9.4.14 (exc) |
| splunk | splunk_secure_gateway | to 3.10.9 (exc) |
| splunk | splunk_secure_gateway | to 3.9.23 (exc) |
| splunk | splunk_secure_gateway | to 3.8.70 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |