Information disclosure in Splunk Enterprise - CVE-2026-76262
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication in the Prometheus metrics endpoint of the Edge Processor SPL2 Preview sidecar when exposing service metrics. A remote attacker can send requests to the metrics endpoint to retrieve runtime and build metadata.