Unauthorized Signature Request Vulnerability in Splunk Enterprise and Splunk Secure Gateway
CVE-2026-76272

4.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
7 October 2026

What is CVE-2026-76272?

An authorization bypass vulnerability exists in Splunk Enterprise and Splunk Secure Gateway, allowing unauthorized users to request signatures on potentially malicious payloads. This issue arises because the Splunk Secure Gateway does not adequately verify the user's authorization levels for signature requests, leading to a serious security risk. Affected users are encouraged to upgrade to the latest protected versions to mitigate this vulnerability.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.3

Splunk Enterprise 10.2 < 10.2.7

Splunk Enterprise 10.0 < 10.0.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.