Server-Side Request Forgery Vulnerability in Splunk Enterprise and Secure Gateway
CVE-2026-76347
5.4MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-76347?
In specific versions of Splunk Enterprise and Splunk Secure Gateway, a flaw allows unauthorized users to exploit server-side request forgery (SSRF) vulnerabilities. This security issue enables users without administrative privileges to send authenticated requests to internal Splunk services through report notifications. Consequently, this can lead to manipulation of the Search Head Cluster state and potential denial of service. The root of this issue lies in the lack of validation for report notification path values before processing internal requests.
Affected Version(s)
Splunk Enterprise 10.4 < 10.4.2
Splunk Enterprise 10.2 < 10.2.6
Splunk Enterprise 10.0 < 10.0.9