Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise Representational State Transfer (REST) API using a system-level session token and modify the Splunk platform configuration. The user could then obtain a session token without a password and use it to access all relevant data and affect system integrity. The vulnerability is possible because Splunk Secure Gateway does not validate decoded report notification identifiers before using them to construct requests to the Splunk Enterprise REST API.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery in the Splunk Secure Gateway report notification API. An authenticated user who is not an admin or power role can create a crafted notification that causes the gateway to issue an internal request to the Splunk Enterprise REST API using a system‑level session token. The gateway then modifies platform configuration. The attacker can subsequently generate a new session token without a password and gain full read‑write access to all data, effectively compromising system integrity.

Affected Systems

Affected products are Splunk Enterprise and Splunk Secure Gateway. For Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, or 9.4.14 any role below admin or power can trigger the flaw. Splunk Secure Gateway versions before 3.10.9, 3.9.23, or 3.8.70 are also vulnerable. No other products or versions were identified by the CNA.

Risk and Exploitability

The CVSS score of 8.8 indicates a high impact with ample privilege escalation potential. The EPSS value is unavailable, so historical exploitation data is unclear. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is likely network‑bound SSRF through the REST API of Secure Gateway, requiring the ability to send crafted report notifications, which is generally limited to users with reporting permissions but not to admin or power roles.

Generated by OpenCVE AI on August 20, 2026 at 10:48 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, or higher.


Vendor Workaround

Turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to at least 10.4.2 (or 10.2.6, 10.0.9, 9.4.14 respectively) and upgrade Splunk Secure Gateway to at least 3.10.9 (or 3.9.23, 3.8.70 respectively).
  • If immediate upgrade is not feasible, disable or uninstall the Splunk Secure Gateway app to eliminate the SSRF entry point, noting that this may affect Splunk Mobile, Spacebridge, and Mission Control.
  • Restrict report notification creation and execution permissions to users with the admin or power role, or otherwise remove report notification capabilities from lower‑privilege user accounts.

Generated by OpenCVE AI on August 20, 2026 at 10:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
Vendors & Products Splunk splunk

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway
Vendors & Products Splunk
Splunk splunk Enterprise
Splunk splunk Secure Gateway

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise Representational State Transfer (REST) API using a system-level session token and modify the Splunk platform configuration. The user could then obtain a session token without a password and use it to access all relevant data and affect system integrity. The vulnerability is possible because Splunk Secure Gateway does not validate decoded report notification identifiers before using them to construct requests to the Splunk Enterprise REST API.
Title Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secure Gateway
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Splunk Splunk Enterprise Splunk Secure Gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-21T03:56:18.924Z

Reserved: 2026-08-19T12:02:03.628Z

Link: CVE-2026-76351

cve-icon Vulnrichment

Updated: 2026-08-20T16:23:44.643Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:20.070

Modified: 2026-08-21T19:17:12.927

Link: CVE-2026-76351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)