CVE-2026-76265
Received Received - Intake

Authentication Bypass in Splunk Secure Gateway

Vulnerability report for CVE-2026-76265, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Splunk Splunk Enterprise 10.4
Splunk Splunk Enterprise 10.2
Splunk Splunk Enterprise 10.0
Splunk Splunk Enterprise 9.4
Splunk Splunk Secure Gateway 3.10
Splunk Splunk Secure Gateway 3.9
Splunk Splunk Secure Gateway 3.8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise and Splunk Secure Gateway. A non-admin user could access privileged functionality in Splunk Secure Gateway and cause it to sign attacker-controlled payloads. This happens because certain REST API endpoints do not check authorization before processing requests.

Detection Guidance

This vulnerability can be detected by checking the versions of Splunk Enterprise and Splunk Secure Gateway installed on your systems. Compare them against the fixed versions: Splunk Enterprise (10.4.3, 10.2.7, 10.0.10, 9.4.15) and Splunk Secure Gateway (3.10.11, 3.9.25, 3.8.72). If versions are below these, the system is vulnerable.

Impact Analysis

An attacker could exploit this to trick Splunk Secure Gateway into signing malicious payloads, potentially leading to unauthorized actions or data manipulation. This could compromise the integrity of Splunk's operations and expose sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access or data tampering, violating compliance requirements for data protection and integrity. Organizations using affected Splunk versions may fail to meet GDPR or HIPAA standards due to insufficient access controls.

Mitigation Strategies

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, or 9.4.15, and Splunk Secure Gateway to versions 3.10.11, 3.9.25, or 3.8.72 or later to address the authorization bypass in REST API endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76265. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart