Server-Side Request Forgery (SSRF) in Splunk Enterprise - CVE-2026-76347
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to send system-authenticated requests to internal services.
The vulnerability exists due to server-side request forgery in Splunk Secure Gateway report notifications when validating report notification path values. A remote user can send crafted report notification requests to cause system-authenticated requests to internal Splunk services.