cbcvebase.
CVE-2026-76347
published 2026-08-19

CVE-2026-76347: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does…

PriorityP431medium5.4CVSS 3.1
AVNACLPRLUINSUCNILAL
EPSS
0.21%
10.9th percentile
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.

Affected

14 ranges
VendorProductVersion rangeFixed in
splunksplunk>= 10.0.0 < 10.0.910.0.9
splunksplunk>= 10.2.0 < 10.2.610.2.6
splunksplunk>= 10.4.0 < 10.4.210.4.2
splunksplunk>= 9.4.0 < 9.4.149.4.14
splunksplunk_enterprise>= 10.0 < 10.0.910.0.9
splunksplunk_enterprise>= 10.2 < 10.2.610.2.6
splunksplunk_enterprise>= 10.4 < 10.4.210.4.2
splunksplunk_enterprise>= 9.4 < 9.4.149.4.14
splunksplunk_secure_gateway>= 3.10 < 3.10.93.10.9
splunksplunk_secure_gateway>= 3.10.0 < 3.10.93.10.9
splunksplunk_secure_gateway>= 3.8 < 3.8.703.8.70
splunksplunk_secure_gateway>= 3.8.0 < 3.8.703.8.70
splunksplunk_secure_gateway>= 3.9 < 3.9.233.9.23
splunksplunk_secure_gateway>= 3.9.0 < 3.9.233.9.23
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.