Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web. The vulnerability is possible because production JavaScript bundles for the app contain embedded source maps that include original source code. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Splunk Observability Cloud previews (https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.4/observability/splunk-observability-cloud-previews), and Navigating Splunk Web (https://help.splunk.com/en/splunk-enterprise/search/search-tutorial/10.4/part-1-getting-started/navigating-splunk-web) in the Splunk documentation.

Splunk Enterprise versions 9.4.x are not affected.
Published: 2026-10-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 an authenticated user who does not hold the \"admin\" or \"power\" roles can obtain the original JavaScript source code for the Discover Splunk Observability Cloud app through the Splunk Web interface. The flaw is caused by the presence of embedded source maps in the production bundles, which expose the code to anyone who can access the web UI. This is an information exposure vulnerability classified as CWE‑1188 and does not provide code execution, privilege escalation, or other direct system compromise.

Affected Systems

The affected product is Splunk Enterprise. All releases prior to versions 10.4.3, 10.2.7, and 10.0.10 are vulnerable; the 9.4.x series is not affected. The issue originates from the Discover Splunk Observability Cloud app bundled with these releases.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only a standard user account with access to Splunk Web; the attacker can thus retrieve the app’s source code by navigating the web interface. No additional privileges or external exploits are needed. The likely attack vector is network access to the Splunk Web portal, with the threat confined to information disclosure rather than system compromise.

Generated by OpenCVE AI on October 8, 2026 at 01:36 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


Vendor Workaround

Turn off or remove the Discover Splunk Observability Cloud app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, 9.4.15, or later.
  • Turn off or remove the Discover Splunk Observability Cloud app.
  • Review role configurations to ensure low‑privileged users cannot access the app’s source maps through Splunk Web.

Generated by OpenCVE AI on October 8, 2026 at 01:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web. The vulnerability is possible because production JavaScript bundles for the app contain embedded source maps that include original source code. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Splunk Observability Cloud previews (https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.4/observability/splunk-observability-cloud-previews), and Navigating Splunk Web (https://help.splunk.com/en/splunk-enterprise/search/search-tutorial/10.4/part-1-getting-started/navigating-splunk-web) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected.
Title Information Disclosure in the Discover Splunk Observability Cloud app through Splunk Web for Splunk Enterprise
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-08T18:00:58.238Z

Reserved: 2026-08-19T12:02:03.621Z

Link: CVE-2026-76276

cve-icon Vulnrichment

Updated: 2026-10-08T18:00:53.256Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T21:17:18.760

Modified: 2026-10-08T20:08:45.857

Link: CVE-2026-76276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T01:45:09Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default