CVE-2026-76272
Missing Access Control through the REST API in Splunk Secure Gateway
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72 are also affected. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Weakness: CWE-862
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Splunk Enterprise | SIEM & Log Management | cna-assigner |
| Cisco | Splunk Secure Gateway | SIEM & Log Management | cna-assigner |
Vendor-reported products (2)
- Splunk · Splunk Enterprise
- Splunk · Splunk Secure Gateway
Credit
Gabriel Nitu, Splunk
Vendor remediation
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher. Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher.