{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-76265","assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","state":"PUBLISHED","assignerShortName":"cisco","dateReserved":"2026-08-19T12:02:03.620Z","datePublished":"2026-10-07T20:46:29.253Z","dateUpdated":"2026-10-07T20:46:29.253Z"},"containers":{"cna":{"affected":[{"product":"Splunk Enterprise","vendor":"Splunk","versions":[{"version":"10.4","status":"affected","versionType":"custom","lessThan":"10.4.3"},{"version":"10.2","status":"affected","versionType":"custom","lessThan":"10.2.7"},{"version":"10.0","status":"affected","versionType":"custom","lessThan":"10.0.10"},{"version":"9.4","status":"affected","versionType":"custom","lessThan":"9.4.15"}],"modules":["REST API"]},{"product":"Splunk Secure Gateway","vendor":"Splunk","versions":[{"version":"3.10","status":"affected","versionType":"custom","lessThan":"3.10.11"},{"version":"3.9","status":"affected","versionType":"custom","lessThan":"3.9.25"},{"version":"3.8","status":"affected","versionType":"custom","lessThan":"3.8.72"}],"modules":["REST API"]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/markdown","value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the \"admin\" or \"power\" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests."}],"value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the \"admin\" or \"power\" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests."}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001"}],"title":"Improper Access Control through REST API Endpoints in Splunk Secure Gateway","datePublic":"2026-10-07T00:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","type":"cwe","cweId":"CWE-284","description":"The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}]}],"source":{"advisory":"SVD-2026-1001","discovery":""},"providerMetadata":{"orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco","dateUpdated":"2026-10-07T20:46:29.253Z"},"metrics":[{"cvssV3_1":{"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1","baseScore":6.5,"baseSeverity":"MEDIUM"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"solutions":[{"lang":"en","value":"Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.\n\nUpgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher."}],"workarounds":[{"lang":"en","value":"Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app."}],"credits":[{"lang":"en","value":"Younes Zendour (m3l4n0ff)","type":"reporter"}]}}}