REST API Vulnerability in Splunk Enterprise by Splunk
CVE-2026-76278

4.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
7 October 2026

What is CVE-2026-76278?

In specific versions of Splunk Enterprise, a security flaw allows users with the edit_spl2_module_permissions role to exploit the REST API. This exploitation could enable unauthorized access to SPL2 module permissions that the user is not entitled to view, as the application fails to ensure that the user possesses the necessary permissions to access the requested module. This vulnerability underscores the importance of strict access controls and proper permissions verification in preventing unauthorized information disclosure.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.3

Splunk Enterprise 10.2 < 10.2.7

Splunk Enterprise 10.0 < 10.0.10

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.