CVE-2026-76390
Received Received - Intake

Information Disclosure in Cisco Talos Intelligence for Enterprise Security Cloud

Vulnerability report for CVE-2026-76390, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and authentication model. The vulnerability is possible because the generated OpenAPI specification is packaged in a static file path that Splunk Web serves without authentication. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cisco talos_intelligence 1.0.3
splunk splunk 8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3. An unauthenticated user can access the OpenAPI specification through Splunk Web static file paths. This exposes REST API endpoints and authentication details, enabling reconnaissance without needing credentials.

Detection Guidance

Check Splunk Web static file paths for the exposed OpenAPI specification. Look for unauthorized access attempts to paths like /en-US/static/app/cisco_talos_intelligence/openapi.json. Review Splunk logs for unusual requests to these paths.

Impact Analysis

An attacker could use the exposed API details to map out the system, identify potential weaknesses, and plan further attacks. This increases the risk of unauthorized access or data breaches if combined with other vulnerabilities.

Compliance Impact

This vulnerability could lead to unauthorized data access, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance penalties if sensitive data is exposed due to insufficient access controls.

Mitigation Strategies

Upgrade Cisco Talos Intelligence for Enterprise Security Cloud to version 1.0.3 or later. Ensure Splunk Web static file paths are properly secured and require authentication. Restrict access to the OpenAPI specification file.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76390. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart