CVE-2026-76347
published 2026-08-19CVE-2026-76347: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does…
PriorityP431medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.21%
10.9th percentile
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| splunk | splunk | >= 10.0.0 < 10.0.9 | 10.0.9 |
| splunk | splunk | >= 10.2.0 < 10.2.6 | 10.2.6 |
| splunk | splunk | >= 10.4.0 < 10.4.2 | 10.4.2 |
| splunk | splunk | >= 9.4.0 < 9.4.14 | 9.4.14 |
| splunk | splunk_enterprise | >= 10.0 < 10.0.9 | 10.0.9 |
| splunk | splunk_enterprise | >= 10.2 < 10.2.6 | 10.2.6 |
| splunk | splunk_enterprise | >= 10.4 < 10.4.2 | 10.4.2 |
| splunk | splunk_enterprise | >= 9.4 < 9.4.14 | 9.4.14 |
| splunk | splunk_secure_gateway | >= 3.10 < 3.10.9 | 3.10.9 |
| splunk | splunk_secure_gateway | >= 3.10.0 < 3.10.9 | 3.10.9 |
| splunk | splunk_secure_gateway | >= 3.8 < 3.8.70 | 3.8.70 |
| splunk | splunk_secure_gateway | >= 3.8.0 < 3.8.70 | 3.8.70 |
| splunk | splunk_secure_gateway | >= 3.9 < 3.9.23 | 3.9.23 |
| splunk | splunk_secure_gateway | >= 3.9.0 < 3.9.23 | 3.9.23 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk role
ghsa_unreviewed·2026-08-20
CVE-2026-76347 [MEDIUM] CWE-918 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk role
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.
VulDB
Splunk Enterprise/Secure Gateway Report Notifications server-side request forgery
vuldb·2026-08-20·CVSS 5.4
CVE-2026-76347 [MEDIUM] Splunk Enterprise/Secure Gateway Report Notifications server-side request forgery
A vulnerability has been found in Splunk Enterprise and Secure Gateway and classified as critical. The impacted element is an unknown function of the component Report Notifications. Performing a manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-76347. The attack may be initiated remotely. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published