Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, which are secrets that compromise affected Spacebridge private-key material stored in the app collection, through the Splunk Secure Gateway App Key Value Store Representational State Transfer (REST) API. The vulnerability is possible on instances upgraded from older Splunk Secure Gateway deployments when the private-key migration remains incomplete, leaving key material in a collection with an insecure default access control list.
Published: 2026-08-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In older releases of Splunk Enterprise and Splunk Secure Gateway the default access control list for the Key Value Store REST API is improperly configured. Users without the "admin" or "power" roles can observe the contents of the Spacebridge asymmetric private key collection via the REST interface. This allows them to retrieve secrets that are intended to be protected and can lead to compromise of private key material used by Spacebridge.

Affected Systems

Splunk Enterprise versions lower than 10.4.2, 10.2.6, 10.0.9, and 9.4.14; Splunk Secure Gateway versions lower than 3.10.9, 3.9.23, and 3.8.70. The issue persists on instances upgraded from earlier deployments if migration of key material to the new storage has not been completed, leaving keys exposed with an insecure default ACL.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the vulnerability is only exploitable via the REST API by privileged users within the environment. The EPSS score is not available, and the flaw is not present in CISA's KEV catalog, suggesting that it has not been actively exploited at the time of analysis. Nevertheless, the ability to read protected keys poses a significant risk to confidentiality and integrity, making timely remediation a priority.

Generated by OpenCVE AI on August 20, 2026 at 09:57 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Upgrade Splunk Secure Gateway to versions 3.10.9, 3.9.23, and 3.8.70, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2 or later, 10.2.6 or later, 10.0.9 or later, or 9.4.14 or later
  • Upgrade Splunk Secure Gateway to version 3.10.9 or later, 3.9.23 or later, or 3.8.70 or later
  • If an upgrade is not possible, disable or remove the Splunk Secure Gateway app, ensuring that no applications rely on its functionality; otherwise maintain the app only if the migration of key material has been verified and the collection’s ACL has been secured

Generated by OpenCVE AI on August 20, 2026 at 09:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
Vendors & Products Splunk splunk

Wed, 19 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway
Vendors & Products Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, which are secrets that compromise affected Spacebridge private-key material stored in the app collection, through the Splunk Secure Gateway App Key Value Store Representational State Transfer (REST) API. The vulnerability is possible on instances upgraded from older Splunk Secure Gateway deployments when the private-key migration remains incomplete, leaving key material in a collection with an insecure default access control list.
Title Insecure Default Access Control List through the REST API in Splunk Secure Gateway
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Splunk Enterprise Splunk Secure Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-26T19:52:39.938Z

Reserved: 2026-08-19T12:02:03.619Z

Link: CVE-2026-76261

cve-icon Vulnrichment

Updated: 2026-08-26T19:52:32.954Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:14.193

Modified: 2026-08-26T20:18:00.430

Link: CVE-2026-76261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:00:07Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource