Unauthenticated Access Vulnerability in Cisco Talos Intelligence for Splunk Web
CVE-2026-76390
5.3MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-76390?
In versions earlier than 1.0.3 of Cisco Talos Intelligence for Enterprise Security Cloud, an unauthenticated user could exploit a vulnerability to access the OpenAPI specification through unsecured static file paths in Splunk Web. This access allows potential attackers to perform reconnaissance on available REST API endpoints and the associated authentication mechanisms, raising concerns about the security posture of deployed instances.
Affected Version(s)
Cisco Talos Intelligence for Enterprise Security Cloud 1.0 < 1.0.3