API Authorization Flaw in Splunk Enterprise Affects User Data Privacy
CVE-2026-76275

4.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
7 October 2026

What is CVE-2026-76275?

A vulnerability exists in Splunk Enterprise versions, where unauthorized users can access sensitive search query text and job metadata belonging to other users. This issue arises from insufficient enforcement of user authorization within the REST API, allowing information exposure such as job identifiers, dispatch parameters, and execution metadata. Users without 'admin' or 'power' roles could exploit this lapse to gain insights into other users' data workflows, posing significant risks to data privacy and security.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.3

Splunk Enterprise 10.2 < 10.2.7

Splunk Enterprise 10.0 < 10.0.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.