CVE-2026-76274
Received Received - Intake

Outbound Request Redirection in Splunk Enterprise

Vulnerability report for CVE-2026-76274, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens (https://help.splunk.com/en/splunk-observability-cloud/administer/authentication-and-security/authentication-tokens) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Splunk Splunk Enterprise 10.4
Splunk Splunk Enterprise 10.2
Splunk Splunk Enterprise 10.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10. A user with a role containing the read_o11y_content capability can redirect outbound requests from Splunk App for Splunk Observability Cloud to an attacker-controlled host. This exposes the configured Observability Cloud API token because the app does not fully validate the destination of outbound requests.

Detection Guidance

Check Splunk Enterprise versions for affected releases (below 10.4.3, 10.2.7, or 10.0.10). Review REST API logs for outbound requests from Splunk App for Splunk Observability Cloud to unexpected hosts. Inspect network traffic for unauthorized API token disclosures.

Impact Analysis

An attacker could exploit this to steal the Observability Cloud API token, potentially gaining unauthorized access to sensitive data or systems. This could lead to data breaches, unauthorized actions, or further network compromise depending on the token's permissions.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA requirements for data protection and access controls. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, or 10.0.10 or later. Restrict the read_o11y_content capability to trusted users only. Monitor outbound requests from Splunk App for Splunk Observability Cloud for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76274. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart