Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Gateway administration privileges could access Mobile Device Management signing secrets that compromise all affected mobile-device enrollment trust through Splunk Secure Gateway. The vulnerability is possible because Splunk Secure Gateway Representational State Transfer (REST) API endpoints for deployment bundle, Security Assertion Markup Language setup, and companion app workflows do not require Splunk Secure Gateway administration privileges before processing requests.
Published: 2026-08-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a missing authorization weakness in the Splunk Secure Gateway REST API. API endpoints that deploy bundles, configure SAML, and manage companion apps can be accessed without Splunk Secure Gateway administrator privileges. An attacker who has permission to list storage passwords can retrieve signing secrets used for mobile‑device enrollment, breaking the trust chain for all devices and exposing them to compromise. The weakness maps to CWE‑862, Unauthorized Access.

Affected Systems

Affected products are Splunk Enterprise and Splunk Secure Gateway. Vulnerable Splunk Enterprise releases include any version prior to 10.4.2, 10.2.6, 10.0.9, or 9.4.14. Vulnerable Splunk Secure Gateway releases include any version prior to 3.10.10, 3.9.24, or 3.8.71.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate impact on confidentiality, integrity, and availability. No EPSS score is provided, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and requires only API access; an attacker must possess a role that can list storage passwords. Once that role is available, the attacker can call the vulnerable endpoints and harvest the signing secrets for all enrolled devices.

Generated by OpenCVE AI on August 20, 2026 at 08:55 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Upgrade Splunk Secure Gateway to versions 3.10.10, 3.9.24, and 3.8.71, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2 or later, 10.2.6 or later, 10.0.9 or later, or 9.4.14 or later.
  • Upgrade Splunk Secure Gateway to version 3.10.10 or later, 3.9.24 or later, or 3.8.71 or later.
  • If an upgrade is not possible, disable or remove the Splunk Secure Gateway app until it can be patched.

Generated by OpenCVE AI on August 20, 2026 at 08:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
Vendors & Products Splunk splunk

Thu, 20 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway
Vendors & Products Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who holds a Splunk role with permissions to list storage passwords but does not hold Splunk Secure Gateway administration privileges could access Mobile Device Management signing secrets that compromise all affected mobile-device enrollment trust through Splunk Secure Gateway. The vulnerability is possible because Splunk Secure Gateway Representational State Transfer (REST) API endpoints for deployment bundle, Security Assertion Markup Language setup, and companion app workflows do not require Splunk Secure Gateway administration privileges before processing requests.
Title Missing Authorization through REST API Endpoints in Splunk Secure Gateway
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Splunk Enterprise Splunk Secure Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:23:27.620Z

Reserved: 2026-08-19T12:02:03.619Z

Link: CVE-2026-76257

cve-icon Vulnrichment

Updated: 2026-08-26T14:49:09.879Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:13.670

Modified: 2026-08-26T16:16:38.733

Link: CVE-2026-76257

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T09:00:05Z

Weaknesses