Server-Side Request Forgery (SSRF) in Splunk Enterprise - CVE-2026-76351
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to send system-authenticated REST API requests.
The vulnerability exists due to server-side request forgery in Splunk Secure Gateway report notifications when constructing Splunk Enterprise REST API requests from decoded report notification identifiers. A remote user can send crafted report notification data to modify Splunk platform configuration.