Security Flaw in Splunk Enterprise and Splunk Secure Gateway
CVE-2026-76351

8.8HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76351?

A vulnerability exists in Splunk Enterprise and Splunk Secure Gateway, allowing unauthorized users to exploit crafted report notification data. This flaw enables these users to trigger requests to the Splunk Enterprise REST API using session tokens, which can modify platform configurations and access sensitive data without appropriate authentication. The issue arises due to the failure of Splunk Secure Gateway to validate identifiers from decoded notifications, leading to potential breaches in system integrity.

Affected Version(s)

Splunk Enterprise 10.4 < 10.4.2

Splunk Enterprise 10.2 < 10.2.6

Splunk Enterprise 10.0 < 10.0.9

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.