Missing Authorization in Splunk Enterprise - CVE-2026-76257
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive secrets.
The vulnerability exists due to missing authorization in Splunk Secure Gateway REST API endpoints when processing deployment bundle, SAML setup, and companion app workflow requests. A remote user can send REST API requests to access Mobile Device Management signing secrets.
Exploitation requires permissions to list storage passwords without Splunk Secure Gateway administration privileges.