Description
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to an attacker-controlled server. The request could expose tokens that compromise all relevant data and system integrity in the Splunk instance. The vulnerability is possible because the Talos intelligence enrichment REST endpoint accepts the destination for authenticated Splunk management requests from request data. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.
Published: 2026-08-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Server-Side Request Forgery in the Talos intelligence enrichment REST API. A user with the get_talos_enrichment capability can send a specially crafted request that causes the Splunk instance to make an outbound call to an attacker-controlled server. The data received by the server may contain authentication tokens that can compromise all relevant data and system integrity within the Splunk environment. The flaw arises from accepting a destination host from request data without proper validation, a weakness identified as CWE‑918.

Affected Systems

Affected systems are deployments of the Cisco Talos Intelligence for Enterprise Security Cloud Splunk app or add-on whose version is below 1.0.3. This includes all Splunk Enterprise Security instances that have installed the Cisco Talos Intelligence for Enterprise Security Cloud app prior to the release of the 1.0.3 patch.

Risk and Exploitability

The CVSS score of 8.8 classifies this flaw as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack appears to be limited to authenticated users who possess the get_talos_enrichment role, meaning the threat surface depends on internal role assignment. Because the flaw allows an attacker to obtain privileged tokens, the risk of data breach or potential lateral movement is significant.

Generated by OpenCVE AI on August 20, 2026 at 10:35 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the Cisco Talos Intelligence for Enterprise Security Cloud app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade the Cisco Talos Intelligence for Enterprise Security Cloud Splunk app or add‑on to version 1.0.3 or later.
  • If a patch cannot be applied immediately, temporarily disable the Cisco Talos Intelligence for Enterprise Security Cloud app or remove it from the Splunk instance.
  • Review and restrict the get_talos_enrichment capability to only trusted users and ensure role separation; remove this capability from unnecessary accounts.

Generated by OpenCVE AI on August 20, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco talos Intelligence For Enterprise Security Cloud
CPEs cpe:2.3:a:cisco:talos_intelligence_for_enterprise_security_cloud:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco talos Intelligence For Enterprise Security Cloud

Thu, 20 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk cisco Talos Intelligence For Enterprise Security Cloud
Vendors & Products Splunk
Splunk cisco Talos Intelligence For Enterprise Security Cloud

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to an attacker-controlled server. The request could expose tokens that compromise all relevant data and system integrity in the Splunk instance. The vulnerability is possible because the Talos intelligence enrichment REST endpoint accepts the destination for authenticated Splunk management requests from request data. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.
Title Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for Enterprise Security Cloud
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Cisco Talos Intelligence For Enterprise Security Cloud
Splunk Cisco Talos Intelligence For Enterprise Security Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T13:25:45.143Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76389

cve-icon Vulnrichment

Updated: 2026-08-20T13:25:42.480Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:25.220

Modified: 2026-08-21T19:18:35.820

Link: CVE-2026-76389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)