Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability allows a user who does not hold the "admin" or "power" Splunk roles to invoke privileged REST API endpoints in Splunk Secure Gateway. By bypassing the required authorization checks, the attacker can request that the gateway sign attacker‑controlled payloads, effectively enabling them to perform actions with elevated privileges. The primary impact is a privilege escalation that could lead to forging signatures and executing unauthorized requests within the Splunk ecosystem.

Affected Systems

The affected products are Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions earlier than 3.10.11, 3.9.25, and 3.8.72. Users of those releases, regardless of administrative status, are susceptible if they are able to authenticate with a non‑"admin" or "power" Splunk role.

Risk and Exploitability

The CVSS score is 6.5, indicating a moderate severity risk. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack path requires an authenticated user with network access to the REST API; the attacker need not have elevated roles to call the vulnerable endpoints, making the exploitation relatively straightforward for any user who can reach the API. The lack of authorization enforcement means that the exploitation can be carried out remotely over the network or locally if the user has access to Splunk’s API endpoints.

Generated by OpenCVE AI on October 7, 2026 at 22:40 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher. Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher.


Vendor Workaround

Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, or 9.4.15, or higher
  • Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, or 3.8.72, or higher
  • If upgrading is not possible, disable or remove the Splunk Secure Gateway app to eliminate the exposed endpoints

Generated by OpenCVE AI on October 7, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway
Vendors & Products Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.
Title Improper Access Control through REST API Endpoints in Splunk Secure Gateway
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Enterprise Splunk Secure Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:29.253Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76265

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:17.150

Modified: 2026-10-07T21:17:17.150

Link: CVE-2026-76265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:14Z

Weaknesses