Missing Authentication for Critical Function in Splunk Enterprise - CVE-2026-76355
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication in the Edge Processor service endpoint when retrieving pipeline configurations. A remote attacker can send REST API requests to retrieve information contained in Edge Processor pipeline configurations.
Edge Processor must be turned on.