Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.
Published: 2026-08-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An SSRF flaw exists in the report notifications REST API of Splunk Secure Gateway and certain Splunk Enterprise versions. The flaw allows users who do not have admin or power roles to send system‑authenticated requests to internal Splunk services by manipulating the notification path. Attacks can alter the Search Head Cluster state or trigger a denial of service by targeting internal endpoints.

Affected Systems

Affected products are Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions prior to 3.10.9, 3.9.23, and 3.8.70. These versions include the report notifications feature without proper input validation, exposing the SSRF risk.

Risk and Exploitability

CVSS scoring indicates a medium risk with a score of 5.4, and there is no EPSS data or KEV listing, meaning the likelihood of exploitation is currently unknown. Attackers must authenticate as a standard user and craft a report notification request, exploiting an unchecked path value to trigger internal requests; once executed, it can manipulate internal services.

Generated by OpenCVE AI on August 20, 2026 at 07:56 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Upgrade Splunk Secure Gateway to versions 3.10.9, 3.9.23, and 3.8.70, or higher. If you cannot upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later.
  • Upgrade Splunk Secure Gateway to version 3.10.9, 3.9.23, or 3.8.70 or later.
  • If an upgrade is not possible, disable or uninstall the Splunk Secure Gateway app to eliminate the vulnerable API endpoint.

Generated by OpenCVE AI on August 20, 2026 at 07:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
Vendors & Products Splunk splunk

Thu, 20 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway
Vendors & Products Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.
Title Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Splunk Splunk Splunk Enterprise Splunk Secure Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:36.214Z

Reserved: 2026-08-19T12:02:03.628Z

Link: CVE-2026-76347

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:19.553

Modified: 2026-08-21T19:17:09.870

Link: CVE-2026-76347

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)