CVE-2026-76280
Received Received - Intake

Privilege Escalation in Splunk Secure Gateway

Vulnerability report for CVE-2026-76280, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the "admin" or "sc_admin" Splunk roles could modify Splunk Secure Gateway alert and mobile-device recipient data in App Key Value Store (KV Store) collections that later alert and subscription workflows use. The vulnerability is possible because the affected collections allow unrestricted write access instead of limiting writes to authorized Splunk Secure Gateway workflows. For more information see About the app key value store (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/administer-the-app-key-value-store/about-the-app-key-value-store), KV store endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.4/kv-store-endpoints/kv-store-endpoint-descriptions), and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
Splunk Splunk Enterprise 10.4
Splunk Splunk Enterprise 10.2
Splunk Splunk Enterprise 10.0
Splunk Splunk Enterprise 9.4
Splunk Splunk Secure Gateway 3.10
Splunk Splunk Secure Gateway 3.9
Splunk Splunk Secure Gateway 3.8

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise and Splunk Secure Gateway. An authenticated user without admin or sc_admin roles can modify alert and mobile-device recipient data in App Key Value Store collections. The issue occurs because these collections allow unrestricted write access instead of restricting writes to authorized workflows.

Impact Analysis

An attacker could alter alert data or mobile-device recipient lists, potentially causing missed alerts or unauthorized notifications. This could disrupt operations or lead to data leakage if alerts are tampered with.

Mitigation Strategies

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, or 9.4.15, and Splunk Secure Gateway to versions 3.10.11, 3.9.25, or 3.8.72 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76280. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart