User Role Exploit in Splunk Enterprise Affects App Logging Capabilities
CVE-2026-76267
4.3MEDIUM
What is CVE-2026-76267?
In Splunk Enterprise versions prior to 10.4.3, 10.2.7, and 10.0.10, a serious vulnerability allows users with the read_o11y_content role to inject unauthorized entries into the application log via the REST API. This arises from a lack of proper validation of user input in the Splunk App for Splunk O11y Cloud, specifically regarding SignalFlow content. As a result, this could lead to manipulated logs, compromising data integrity and security.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.3
Splunk Enterprise 10.2 < 10.2.7
Splunk Enterprise 10.0 < 10.0.10