Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens (https://help.splunk.com/en/splunk-observability-cloud/administer/authentication-and-security/authentication-tokens) in the Splunk documentation.

Splunk Enterprise versions 9.4.x are not affected.
Published: 2026-10-07
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Token Disclosure via SSRF
Action: Immediate Patch
AI Analysis

Impact

A user with the read_o11y_content capability in Splunk Enterprise can issue outbound requests through the Splunk App for Splunk Observability Cloud’s REST API to an attacker‑controlled host, triggering a Server‑Side Request Forgery that exposes the configured Observability Cloud API token. This flaw stems from insufficient validation of the request destination and is classified as CWE‑918.

Affected Systems

Splunk Enterprise instances running versions below 10.4.3, 10.2.7, or 10.0.10, while 9.4.x versions are unaffected. The vulnerability surfaces only when the Splunk App for Splunk Observability Cloud is installed and a user possessing the read_o11y_content capability is able to invoke the REST API.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, with exploitation requiring privileged read_o11y_content access. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting that while potential for exploitation exists, the likelihood may remain limited. Nonetheless, an attacker who gains the stated role can redirect traffic to arbitrary hosts and capture an authentication token, compromising data security.

Generated by OpenCVE AI on October 7, 2026 at 22:57 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


Vendor Workaround

Turn off or remove the Splunk App for Splunk Observability Cloud. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, or 9.4.15 or later
  • If an upgrade cannot be performed immediately, turn off or remove the Splunk App for Splunk Observability Cloud
  • Review and restrict the read_o11y_content capability in user roles, removing it when not required

Generated by OpenCVE AI on October 7, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens (https://help.splunk.com/en/splunk-observability-cloud/administer/authentication-and-security/authentication-tokens) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.
Title Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observability Cloud
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:34.443Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76274

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:18.477

Modified: 2026-10-07T21:17:18.477

Link: CVE-2026-76274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)