Missing Authorization in Splunk Enterprise - CVE-2026-76257

 

Missing Authorization in Splunk Enterprise - CVE-2026-76257

Published: August 20, 2026


Vulnerability identifier: #VU144435
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76257
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive secrets.

The vulnerability exists due to missing authorization in Splunk Secure Gateway REST API endpoints when processing deployment bundle, SAML setup, and companion app workflow requests. A remote user can send REST API requests to access Mobile Device Management signing secrets.

Exploitation requires permissions to list storage passwords without Splunk Secure Gateway administration privileges.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76257

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins