Server-Side Request Forgery Vulnerability in Splunk Enterprise and Secure Gateway
CVE-2026-76347

5.4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76347?

In specific versions of Splunk Enterprise and Splunk Secure Gateway, a flaw allows unauthorized users to exploit server-side request forgery (SSRF) vulnerabilities. This security issue enables users without administrative privileges to send authenticated requests to internal Splunk services through report notifications. Consequently, this can lead to manipulation of the Search Head Cluster state and potential denial of service. The root of this issue lies in the lack of validation for report notification path values before processing internal requests.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.