Access Control Flaw in Splunk Enterprise and Secure Gateway
CVE-2026-76257
6.5MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-76257?
A security flaw in specific versions of Splunk Enterprise and Splunk Secure Gateway allows users with limited permissions to access sensitive Mobile Device Management signing secrets. This access can compromise the trust associated with mobile-device enrollment. The vulnerability arises from inadequate access controls on REST API endpoints, permitting unauthorized access to critical resources without the necessary administrative privileges. As such, it is essential for users operating affected versions to update their systems to maintain the security and integrity of mobile device management operations.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9