Description
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and authentication model. The vulnerability is possible because the generated OpenAPI specification is packaged in a static file path that Splunk Web serves without authentication. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.
Published: 2026-08-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated user can download the OpenAPI specification exposed through Splunk Web static file paths in Cisco Talos Intelligence for Enterprise Security Cloud versions earlier than 1.0.3. The specification reveals all REST API endpoints and the authentication model, enabling an attacker to plan further attacks against the app. Because the file is served without authentication, the vulnerability allows information disclosure and could serve as a reconnaissance step.

Affected Systems

The affected product is Splunk’s Cisco Talos Intelligence for Enterprise Security Cloud app. Versions below 1.0.3 are vulnerable. Any deployment of the app on Splunk Web exposes the OpenAPI specification to unauthenticated users.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS data is available and the vulnerability is not listed in CISA KEV, suggesting low exploitation probability at present. The attack vector is inferred from the description to be over the network via Splunk Web, as the vulnerability arises when the OpenAPI spec is packaged as a static file served without authentication.

Generated by OpenCVE AI on August 20, 2026 at 10:54 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the Cisco Talos Intelligence for Enterprise Security Cloud app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade each instance of the Cisco Talos Intelligence for Enterprise Security Cloud app to version 1.0.3 or later.
  • If an upgrade cannot be performed immediately, disable or remove the app to stop unauthenticated access to its static files.
  • For environments that must keep the app, restrict web access to Splunk Web or block the static file paths that serve the OpenAPI specification using firewall, VPN, or reverse‑proxy rules.

Generated by OpenCVE AI on August 20, 2026 at 10:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco talos Intelligence For Enterprise Security Cloud
CPEs cpe:2.3:a:cisco:talos_intelligence_for_enterprise_security_cloud:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco talos Intelligence For Enterprise Security Cloud

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk cisco Talos Intelligence For Enterprise Security Cloud
Vendors & Products Splunk
Splunk cisco Talos Intelligence For Enterprise Security Cloud

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and authentication model. The vulnerability is possible because the generated OpenAPI specification is packaged in a static file path that Splunk Web serves without authentication. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.
Title Information Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security Cloud
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Cisco Talos Intelligence For Enterprise Security Cloud
Splunk Cisco Talos Intelligence For Enterprise Security Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:30.600Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76390

cve-icon Vulnrichment

Updated: 2026-08-20T16:20:56.845Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:25.357

Modified: 2026-08-21T19:18:17.943

Link: CVE-2026-76390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor