Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup Language setup and instance settings information through Splunk Secure Gateway Representational State Transfer (REST) API endpoints. The vulnerability is possible because the affected Security Assertion Markup Language setup and instance settings REST API endpoints do not enforce authorization requirements before returning configuration information.
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows a non‑admin or non‑power user in Splunk Enterprise or Splunk Secure Gateway to read security Assertion Markup Language setup and instance settings via REST API endpoints that do not enforce proper authorization. The flaw results in disclosure of sensitive configuration information, potentially exposing details that could assist in further attacks. The weakness is a classic information disclosure, identified as CWE‑200.

Affected Systems

Affected are Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70. The vulnerability impacts both products when the Splunk Secure Gateway app is installed.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate risk. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would need only to authenticate with a non‑admin, non‑power role and make a REST API call over the network to obtain the exposed configuration data. Although there is no EPSS data, the exposure of SAML settings could enable attackers to craft further exploits. The impact is limited to information disclosure, but the specific data revealed may assist in planning additional attacks.

Generated by OpenCVE AI on August 20, 2026 at 10:58 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Upgrade Splunk Secure Gateway to versions 3.10.9, 3.9.23, and 3.8.70, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to 10.4.2 or newer, 10.2.6 or newer, 10.0.9 or newer, or 9.4.14 or newer.
  • Upgrade Splunk Secure Gateway to 3.10.9 or newer, 3.9.23 or newer, or 3.8.70 or newer.
  • If upgrading is not feasible, disable or remove the Splunk Secure Gateway app; if you do not use Mobile, Spacebridge, or Mission Control, removing the app is also acceptable.

Generated by OpenCVE AI on August 20, 2026 at 10:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk Enterprise
Vendors & Products Splunk splunk Enterprise

Thu, 20 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Splunk splunk Secure Gateway
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
Vendors & Products Splunk
Splunk splunk
Splunk splunk Secure Gateway

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup Language setup and instance settings information through Splunk Secure Gateway Representational State Transfer (REST) API endpoints. The vulnerability is possible because the affected Security Assertion Markup Language setup and instance settings REST API endpoints do not enforce authorization requirements before returning configuration information.
Title Information Exposure through REST API Endpoints in Splunk Secure Gateway
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Splunk Splunk Enterprise Splunk Secure Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:23:35.816Z

Reserved: 2026-08-19T12:02:03.619Z

Link: CVE-2026-76256

cve-icon Vulnrichment

Updated: 2026-08-26T14:49:07.171Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:13.543

Modified: 2026-08-26T16:16:38.603

Link: CVE-2026-76256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:03:00Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor