API Authorization Flaw in Splunk Enterprise Affects User Data Privacy
CVE-2026-76275
4.3MEDIUM
What is CVE-2026-76275?
A vulnerability exists in Splunk Enterprise versions, where unauthorized users can access sensitive search query text and job metadata belonging to other users. This issue arises from insufficient enforcement of user authorization within the REST API, allowing information exposure such as job identifiers, dispatch parameters, and execution metadata. Users without 'admin' or 'power' roles could exploit this lapse to gain insights into other users' data workflows, posing significant risks to data privacy and security.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.3
Splunk Enterprise 10.2 < 10.2.7
Splunk Enterprise 10.0 < 10.0.10