CVE-2026-76278

Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise

Severity
Medium 4.3
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
—
Discovered by
Vendor
Vendor-published field
Published
Oct 7, 2026
Assigned by cisco

Description

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State Transfer (REST) API to access permission grants for SPL2 modules that the user does not have permission to view. The vulnerability is possible because Splunk Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. For more information see Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) and Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.

Weakness: CWE-639

Affected products

Vendor Product Category Matched by
Cisco Splunk Enterprise SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Splunk · Splunk Enterprise

Credit

Gabriel Nitu, Splunk

Vendor remediation

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.

Something wrong here?