Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Splunk Observability Cloud access token stored for the app. With this access, the user could view all relevant data available to that token and make limited changes to Splunk Observability Cloud content. The vulnerability does not affect Splunk Enterprise 9.4 and 9.3 versions. The vulnerability is possible because the app's Representational State Transfer (REST) API endpoint handlers do not enforce the read_o11y_content capability before forwarding requests with the stored access token. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Published: 2026-08-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Splunk App for Splunk Observability Cloud contains REST API endpoints that do not require the read_o11y_content capability. This omission lets a user who is not in the admin or power role trigger requests that the app forwards to Search Observability Cloud, exposing the access token stored for the app. With that token, the attacker can view all information and perform limited changes that the token permits, resulting in a breach of confidentiality and integrity. The flaw is a classic missing authorization vulnerability (CWE‑862).

Affected Systems

Splunk Enterprise deployments running versions earlier than 10.4.2, 10.2.6, or 10.0.9 with the Splunk App for Splunk Observability Cloud installed are vulnerable. Versions 9.4 and 9.3 are unaffected. Any user who is able to access the App’s REST endpoints with a non‑admin or non‑power role can exploit the weakness.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating a high impact if exploited. No EPSS score is available, and the flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog. The primary attack vector is via the App’s REST API, which an attacker can utilize if they have user access to the Splunk Enterprise instance. Although the exact exploitation probability is unknown, the combination of moderate‑high severity and the potential to exfiltrate sensitive data places it in a high‑risk category.

Generated by OpenCVE AI on August 20, 2026 at 09:59 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Turn off or remove the Splunk App for Splunk Observability Cloud. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, or 9.4.14 and later to receive the fix.
  • If upgrading immediately is not feasible, disable or remove the Splunk App for Splunk Observability Cloud to block the exposed REST endpoints.
  • Review and enforce the read_o11y_content capability in custom or third‑party REST handlers to prevent future authorization bypasses.

Generated by OpenCVE AI on August 20, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Splunk Observability Cloud access token stored for the app. With this access, the user could view all relevant data available to that token and make limited changes to Splunk Observability Cloud content. The vulnerability does not affect Splunk Enterprise 9.4 and 9.3 versions. The vulnerability is possible because the app's Representational State Transfer (REST) API endpoint handlers do not enforce the read_o11y_content capability before forwarding requests with the stored access token. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Title Missing Authorization through REST API Endpoints in the Splunk App for Splunk Observability Cloud
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:23:52.622Z

Reserved: 2026-08-19T12:02:03.618Z

Link: CVE-2026-76251

cve-icon Vulnrichment

Updated: 2026-08-26T14:49:04.419Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:12.850

Modified: 2026-08-26T16:16:38.340

Link: CVE-2026-76251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses