Unauthorized Data Modification in Splunk Enterprise and Secure Gateway
CVE-2026-76280
6.3MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 7 October 2026
What is CVE-2026-76280?
In several versions of Splunk Enterprise and Splunk Secure Gateway, an authenticated user lacking sufficient permissions can alter alert and mobile-device recipient data within collections of the App Key Value Store. This vulnerability arises due to improperly configured access controls, allowing unrestricted write access in crucial data workflows. As a result, these unauthorized changes can have serious implications for alert and subscription processes. Proper role-based access management is essential to prevent such exploitation.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.3
Splunk Enterprise 10.2 < 10.2.7
Splunk Enterprise 10.0 < 10.0.10