CVE-2026-76355
Received Received - Intake

Unauthenticated Information Disclosure in Splunk Enterprise Edge Processor

Vulnerability report for CVE-2026-76355, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the information contained in Edge Processor pipeline configurations through a Representational State Transfer (REST) API endpoint when Edge Processor is turned on. The vulnerability does not affect versions prior to 10.4. The vulnerability exists because the Edge Processor service endpoint lacks authentication controls. For more information see System architecture of the Edge Processor solution (https://help.splunk.com/en/splunk-enterprise/process-data-at-the-edge/use-edge-processors-for-splunk-enterprise/10.4/how-the-edge-processor-solution-works/system-architecture-of-the-edge-processor-solution) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
splunk splunk_enterprise to 10.4.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Splunk Enterprise 10.4 versions below 10.4.2 allows an unauthenticated user to access Edge Processor pipeline configurations through a REST API endpoint when Edge Processor is enabled. The issue occurs because the endpoint lacks proper authentication controls.

Detection Guidance

Check Splunk Enterprise version with 'splunk version' command. If version is below 10.4.2 and Edge Processor is enabled, the system is vulnerable. Inspect REST API endpoints for unauthenticated access to Edge Processor configurations.

Impact Analysis

An attacker could exploit this to retrieve sensitive configuration details from Edge Processor pipelines, potentially leading to unauthorized access or misuse of data processing settings.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating compliance requirements such as GDPR or HIPAA, which mandate strict access controls and data protection measures.

Mitigation Strategies

Upgrade Splunk Enterprise to version 10.4.2 or later. Disable Edge Processor if not needed. Implement network-level access controls to restrict API endpoint access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76355. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart