Unauthenticated Access Vulnerability in Cisco Talos Intelligence for Splunk Web
CVE-2026-76390

5.3MEDIUM

What is CVE-2026-76390?

In versions earlier than 1.0.3 of Cisco Talos Intelligence for Enterprise Security Cloud, an unauthenticated user could exploit a vulnerability to access the OpenAPI specification through unsecured static file paths in Splunk Web. This access allows potential attackers to perform reconnaissance on available REST API endpoints and the associated authentication mechanisms, raising concerns about the security posture of deployed instances.

Affected Version(s)

Cisco Talos Intelligence for Enterprise Security Cloud 1.0 < 1.0.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.