Use of Hard-coded Cryptographic Key in Splunk Enterprise - CVE-2026-76258
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose mobile user tokens.
The vulnerability exists due to use of a hard-coded cryptographic key in the Splunk Secure Gateway companion app registration handler when registering callback URLs. A remote user can register an arbitrary companion app to forward mobile user requests to an attacker-controlled URL.