CVE-2026-76351
published 2026-08-19CVE-2026-76351: In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does…
PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.24%
15.6th percentile
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise Representational State Transfer (REST) API using a system-level session token and modify the Splunk platform configuration. The user could then obtain a session token without a password and use it to access all relevant data and affect system integrity. The vulnerability is possible because Splunk Secure Gateway does not validate decoded report notification identifiers before using them to construct requests to the Splunk Enterprise REST API.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| splunk | splunk | >= 10.0.0 < 10.0.9 | 10.0.9 |
| splunk | splunk | >= 10.2.0 < 10.2.6 | 10.2.6 |
| splunk | splunk | >= 10.4.0 < 10.4.2 | 10.4.2 |
| splunk | splunk | >= 9.4.0 < 9.4.14 | 9.4.14 |
| splunk | splunk_enterprise | >= 10.0 < 10.0.9 | 10.0.9 |
| splunk | splunk_enterprise | >= 10.2 < 10.2.6 | 10.2.6 |
| splunk | splunk_enterprise | >= 10.4 < 10.4.2 | 10.4.2 |
| splunk | splunk_enterprise | >= 9.4 < 9.4.14 | 9.4.14 |
| splunk | splunk_secure_gateway | >= 3.10 < 3.10.9 | 3.10.9 |
| splunk | splunk_secure_gateway | >= 3.10.0 < 3.10.9 | 3.10.9 |
| splunk | splunk_secure_gateway | >= 3.8 < 3.8.70 | 3.8.70 |
| splunk | splunk_secure_gateway | >= 3.8.0 < 3.8.70 | 3.8.70 |
| splunk | splunk_secure_gateway | >= 3.9 < 3.9.23 | 3.9.23 |
| splunk | splunk_secure_gateway | >= 3.9.0 < 3.9.23 | 3.9.23 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk role
ghsa_unreviewed·2026-08-20
CVE-2026-76351 [HIGH] CWE-918 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk role
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use crafted report notification data to cause Splunk Secure Gateway to send a request to the Splunk Enterprise Representational State Transfer (REST) API using a system-level session token and modify the Splunk platform configuration. The user could then obtain a session token without a password and use it to access all relevant data and affect system integrity. The vulnerability is possible because Splunk Secure Gateway does not validate decoded report notification identifiers before using them to construct requests to the Splunk Enterprise REST API.
VulDB
Splunk Enterprise/Secure Gateway Report Notification improper authorization
vuldb·2026-08-20·CVSS 8.8
CVE-2026-76351 [HIGH] Splunk Enterprise/Secure Gateway Report Notification improper authorization
A vulnerability classified as very critical was found in Splunk Enterprise and Secure Gateway. This impacts an unknown function of the component Report Notification Handler. Such manipulation leads to improper authorization.
This vulnerability is uniquely identified as CVE-2026-76351. The attack can be launched remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published