CVE-2026-76327
Received Received - Intake

Cross-Site Request Forgery in Splunk Enterprise and Splunk Secure Gateway

Vulnerability report for CVE-2026-76327, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, an unauthenticated user could trick a user who holds the "admin" or "sc_admin" Splunk roles into opening a crafted Splunk Web Uniform Resource Locator (URL). The resulting dashboard searches could run arbitrary Search Processing Language (SPL) commands with the permissions available to the affected user. The commands could expose all relevant data available to that user and affect search results or lookup data. The vulnerability is possible because Splunk Secure Gateway dashboards do not correctly neutralize caller-supplied values before using them in dashboard searches. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The unauthenticated user should not be able to exploit the vulnerability at will.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
splunk splunk_enterprise to 10.4.2 (exc)
splunk splunk_secure_gateway to 3.10.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise and Splunk Secure Gateway. An unauthenticated attacker can trick an admin or sc_admin user into clicking a malicious URL. This URL triggers dashboard searches that run arbitrary SPL commands with the user's permissions. The commands could expose data, modify search results, or alter lookup data.

Detection Guidance

Detection requires checking Splunk Enterprise and Splunk Secure Gateway versions against the affected releases. Use Splunk's built-in version check or run commands like 'splunk show version' in the Splunk CLI to verify installed versions.

Impact Analysis

If exploited, this vulnerability could allow an attacker to access sensitive data available to admin users, manipulate search results, or modify lookup data. The impact depends on the permissions of the tricked user. It requires social engineering to initiate the request in the user's browser.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Exposure of personal or health data could result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, or 9.4.14, and Splunk Secure Gateway to versions 3.10.9, 3.9.23, or 3.8.70. Disable unnecessary admin roles and restrict user permissions until updates are applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76327. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart