{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-76272","assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","state":"PUBLISHED","assignerShortName":"cisco","dateReserved":"2026-08-19T12:02:03.620Z","datePublished":"2026-10-07T20:46:33.402Z","dateUpdated":"2026-10-07T20:46:33.402Z"},"containers":{"cna":{"affected":[{"product":"Splunk Enterprise","vendor":"Splunk","versions":[{"version":"10.4","status":"affected","versionType":"custom","lessThan":"10.4.3"},{"version":"10.2","status":"affected","versionType":"custom","lessThan":"10.2.7"},{"version":"10.0","status":"affected","versionType":"custom","lessThan":"10.0.10"},{"version":"9.4","status":"affected","versionType":"custom","lessThan":"9.4.15"}],"modules":["REST API"]},{"product":"Splunk Secure Gateway","vendor":"Splunk","versions":[{"version":"3.10","status":"affected","versionType":"custom","lessThan":"3.10.11"},{"version":"3.9","status":"affected","versionType":"custom","lessThan":"3.9.25"},{"version":"3.8","status":"affected","versionType":"custom","lessThan":"3.8.72"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/markdown","value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the \"admin\" or \"power\" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72 are also affected. For more information see [Define roles on the Splunk platform with capabilities](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation."}],"value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the \"admin\" or \"power\" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72 are also affected. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation."}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001"}],"title":"Missing Access Control through the REST API in Splunk Secure Gateway","datePublic":"2026-10-07T00:00:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","type":"cwe","cweId":"CWE-862","description":"The software does not perform an authorization check when an actor attempts to access a resource or perform an action."}]}],"source":{"advisory":"SVD-2026-1001","discovery":"INTERNAL"},"providerMetadata":{"orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco","dateUpdated":"2026-10-07T20:46:33.402Z"},"metrics":[{"cvssV3_1":{"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1","baseScore":4.3,"baseSeverity":"MEDIUM"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"solutions":[{"lang":"en","value":"Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.\n\nUpgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher."}],"workarounds":[{"lang":"en","value":"Turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app."}],"credits":[{"lang":"en","value":"Gabriel Nitu, Splunk","type":"finder"}]}}}