Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and cause Splunk Secure Gateway to forward mobile user requests, including tokens that compromise all relevant data available to the affected mobile user, to an attacker-controlled Uniform Resource Locator (URL). The vulnerability is possible because a hard-coded cryptographic key in the Splunk Secure Gateway companion app registration handler allows for arbitrary callback URL registration without restriction. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Published: 2026-08-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A hard‑coded cryptographic key in the Splunk Secure Gateway companion app registration handler allows a user who does not hold the 'admin' or 'power' roles to register an arbitrary callback URL. The attacker can then cause the gateway to forward mobile user requests, including authentication tokens, to an attacker‑controlled URL. This results in token compromise and potential access to all data available to the affected mobile user. The vulnerability is characterized as a privilege escalation and credential theft flaw, given its reliance on a stored key and its ability to modify traffic flows.

Affected Systems

Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71 are affected. These products are used to manage mobile connectivity and secure user sessions, meaning the flaw applies to any deployment using the affected releases.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the flaw is not listed in CISA KEV, suggesting no known widespread exploitation yet. The likely attack vector is via the Splunk user interface where a non‑privileged user can register a companion app. Exploitation requires the attacker to act as the user performing the registration, so remote or automated attacks are less likely, but the impact on data confidentiality is serious if the attack succeeds.

Generated by OpenCVE AI on August 20, 2026 at 09:58 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Upgrade Splunk Secure Gateway to versions 3.10.10, 3.9.24, and 3.8.71, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2 or later, or 10.2.6, 10.0.9, or 9.4.14 depending on the current release. Upgrade Splunk Secure Gateway to version 3.10.10 or later, or 3.9.24 or 3.8.71 if applicable.
  • If upgrading is not immediately possible, disable or remove the Splunk Secure Gateway app. Only use the app if required for mobile, Spacebridge, or Mission Control; otherwise consider turning it off to remove the attack surface.
  • Follow Splunk’s guidance on managing app and add‑on objects to ensure that only authorized users can install or configure the Secure Gateway app.

Generated by OpenCVE AI on August 20, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway
Vendors & Products Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71, a user who does not hold the "admin" or "power" Splunk roles could register an arbitrary companion app and cause Splunk Secure Gateway to forward mobile user requests, including tokens that compromise all relevant data available to the affected mobile user, to an attacker-controlled Uniform Resource Locator (URL). The vulnerability is possible because a hard-coded cryptographic key in the Splunk Secure Gateway companion app registration handler allows for arbitrary callback URL registration without restriction. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Title Use of Hard-coded Cryptographic Key through Companion App Registration in Splunk Secure Gateway
Weaknesses CWE-321
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Splunk Enterprise Splunk Secure Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T15:23:19.681Z

Reserved: 2026-08-19T12:02:03.619Z

Link: CVE-2026-76258

cve-icon Vulnrichment

Updated: 2026-08-26T14:49:12.077Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:13.793

Modified: 2026-08-26T16:16:38.857

Link: CVE-2026-76258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key