Description
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is possible because the Prometheus metrics endpoint in the Edge Processor SPL2 Preview sidecar lacks authentication, which lets any client that can reach the sidecar retrieve the metrics without credentials. For more information see About Splunk sidecars (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/splunk-sidecars/about-splunk-sidecars) in the Splunk documentation.
Published: 2026-08-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the Prometheus metrics endpoint of the Edge Processor SPL2 Preview sidecar running in Splunk Enterprise. Because the endpoint does not enforce authentication, any client that can reach the sidecar can read service metrics that expose runtime and build metadata. This information could reveal internal network structure, configuration details, and other sensitive data, potentially assisting an adversary in further attacks. The flaw is a classic data disclosure weakness, classified as CWE-200.

Affected Systems

Splunk Enterprise is affected. Versions 10.4.0 through 10.4.1, 10.2.0 through 10.2.5, 10.0.0 through 10.0.8, and 9.4.0 through 9.4.13 are vulnerable because the Prometheus metrics endpoint lacks authentication. All other major releases prior to the specified patch versions are considered safe after applying the update.

Risk and Exploitability

The CVSS score for this vulnerability is 7.5, indicating a high impact on confidentiality. The EPSS score is not available, so the current exploitation probability cannot be precisely quantified, but the lack of authentication means the attack vector is essentially any host that can reach the sidecar, which could be an internal or compromised machine. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploit at this time. Nevertheless, the potential for sensitive data exposure justifies prompt remediation.

Generated by OpenCVE AI on August 20, 2026 at 09:23 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to the earliest available patched release: 10.4.2, 10.2.6, 10.0.9, or 9.4.14, depending on your deployment.
  • If an immediate upgrade is not possible, restrict network access to the Edge Processor SPL2 Preview sidecar Prometheus metrics endpoint with firewall rules or ACLs so that only trusted internal hosts can reach it.
  • Verify that the sidecar is no longer exposed to unauthenticated external clients by testing the metrics endpoint after applying network restrictions or the patch, and confirm that authentication is enforced if it becomes required in future releases.

Generated by OpenCVE AI on August 20, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk splunk

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is possible because the Prometheus metrics endpoint in the Edge Processor SPL2 Preview sidecar lacks authentication, which lets any client that can reach the sidecar retrieve the metrics without credentials. For more information see About Splunk sidecars (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/splunk-sidecars/about-splunk-sidecars) in the Splunk documentation.
Title Exposure of Sensitive Information to an Unauthorized Actor through the REST API in Splunk Enterprise
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-19T21:34:19.005Z

Reserved: 2026-08-19T12:02:03.619Z

Link: CVE-2026-76262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:14.323

Modified: 2026-08-20T14:25:19.910

Link: CVE-2026-76262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T09:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor