Arbitrary Companion App Registration Vulnerability in Splunk Enterprise and Secure Gateway
CVE-2026-76258
6.5MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-76258?
In specific versions of Splunk Enterprise and Splunk Secure Gateway, a user without proper privileges can register a malicious companion app. This allows for the interception and forwarding of mobile user requests, exposing sensitive data to attackers. The core issue arises from a hard-coded cryptographic key, which permits unauthorized callback URL registrations. Proper role definitions and access controls are crucial to mitigate this risk.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9