Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search query text and job metadata for jobs that belong to other users, including job identifiers, dispatch parameters, result counts, and execution metadata, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully enforce per-user authorization before it includes job information in search job listings.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access to Search Job Metadata
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows a non‑admin or non‑power user to retrieve query text, job identifiers, dispatch parameters, result counts, and execution metadata for other users’ search jobs via the REST API. The REST service does not perform per‑user authorization before returning job information, so the attacker can gather sensitive search job data that might reveal user intent or system usage patterns. The flaw is classified as improper authorization (CWE‑285).

Affected Systems

Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15 are affected. Any installation using these releases is vulnerable to the unauthorized job‑listing data exposure.

Risk and Exploitability

The reported CVSS score is 4.3, indicating medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The REST API is reachable over the network and requires only an authenticated session that does not have the admin or power role, so an attacker who has obtained or guessed valid Splunk credentials can exploit the flaw. The impact is limited to information disclosure; the CVE does not mention remote code execution or denial of service, and based on the description, no such impact is inferred.

Generated by OpenCVE AI on October 7, 2026 at 23:29 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to the latest patched release (10.4.3, 10.2.7, 10.0.10, 9.4.15 or newer).
  • Restrict access to the REST API job‑listing endpoint by granting permission only to users with admin or power roles.
  • Deploy network segmentation or firewall rules to limit access to the Splunk REST API to trusted networks, and monitor for unusual API activity to detect potential exploitation attempts.

Generated by OpenCVE AI on October 7, 2026 at 23:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search query text and job metadata for jobs that belong to other users, including job identifiers, dispatch parameters, result counts, and execution metadata, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully enforce per-user authorization before it includes job information in search job listings.
Title Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:34.919Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T21:17:18.617

Modified: 2026-10-08T20:08:45.857

Link: CVE-2026-76275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses