Incorrect permission assignment for critical resource in Splunk Enterprise - CVE-2026-76261
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose private keys.
The vulnerability exists due to an insecure default access control list in the Splunk Secure Gateway App Key Value Store REST API when private-key migration remains incomplete. A remote user can send REST API requests to read Spacebridge asymmetric private keys.
Only upgraded instances with incomplete private-key migration are affected.