Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause a denial of service against a Representational State Transfer (REST) API endpoint in the Discover Splunk Observability Cloud app. The vulnerability is possible because the app uses an inefficient regular expression to validate input submitted through the endpoint. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Splunk Observability Cloud previews (https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.4/observability/splunk-observability-cloud-previews), and restmap.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/restmap.conf) in the Splunk documentation.

Splunk Enterprise versions 9.4.x are not affected.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A low‑privileged Splunk user who does not have the "admin" or "power" role can send crafted requests to a REST API endpoint in the Discover Splunk Observability Cloud app. The vulnerability is caused by an inefficient regular expression used to validate input, allowing a denial of service against the endpoint. The flaw identified as CWE‑407, results in service interruption for the app and potentially the entire Splunk Enterprise instance for all users.

Affected Systems

Splunk Enterprise installations that include the Discover Splunk Observability Cloud app and run versions earlier than 10.4.3, 10.2.7, or 10.0.10 are vulnerable. Versions 9.4.x are not affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. However, because any low‑privileged user with access to the API can trigger the fault, organizations need to consider the potential for internal attackers or compromised accounts. The attack vector is likely internal network or authenticated API calls.

Generated by OpenCVE AI on October 7, 2026 at 22:59 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


Vendor Workaround

Turn off or remove the Discover Splunk Observability Cloud app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10 or later to apply the vendor patch.
  • If an upgrade is not immediately possible, turn off or remove the Discover Splunk Observability Cloud app to eliminate the vulnerable endpoint.
  • As a temporary measure, edit the restmap.conf file to disable or block the affected REST API endpoint until a patch or removal is applied.

Generated by OpenCVE AI on October 7, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause a denial of service against a Representational State Transfer (REST) API endpoint in the Discover Splunk Observability Cloud app. The vulnerability is possible because the app uses an inefficient regular expression to validate input submitted through the endpoint. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Splunk Observability Cloud previews (https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.4/observability/splunk-observability-cloud-previews), and restmap.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.0-configuration-file-reference/restmap.conf) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.
Title Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Splunk Enterprise
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-08T18:01:28.447Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76271

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:18.050

Modified: 2026-10-08T18:18:26.677

Link: CVE-2026-76271

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity