CVE-2026-76276
Received Received - Intake

Source Code Exposure in Splunk Enterprise via JavaScript Source Maps

Vulnerability report for CVE-2026-76276, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web. The vulnerability is possible because production JavaScript bundles for the app contain embedded source maps that include original source code. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Splunk Observability Cloud previews (https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.4/observability/splunk-observability-cloud-previews), and Navigating Splunk Web (https://help.splunk.com/en/splunk-enterprise/search/search-tutorial/10.4/part-1-getting-started/navigating-splunk-web) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Splunk Splunk Enterprise 10.4
Splunk Splunk Enterprise 10.2
Splunk Splunk Enterprise 10.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1188 The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10. A low-privileged user without admin or power roles could access original source code for the Discover Splunk Observability Cloud app via Splunk Web. This occurs because production JavaScript bundles contain embedded source maps with the original source code.

Detection Guidance

To detect this vulnerability, check if your Splunk Enterprise version is below 10.4.3, 10.2.7, or 10.0.10. Splunk Enterprise versions 9.4.x are not affected. Verify if the Discover Splunk Observability Cloud app is installed and if low-privileged users can access original source code through Splunk Web.

Impact Analysis

The impact is limited to information disclosure. An attacker could view the original source code of the app, potentially exposing sensitive logic or configurations. However, no direct code execution or data modification is possible.

Mitigation Strategies

Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, or 10.0.10 or later. Remove or restrict access to the Discover Splunk Observability Cloud app for non-admin users. Review and update role-based user access permissions to prevent unauthorized access to source code.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76276. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart