API Exposure in Splunk On-Call App by Splunk
CVE-2026-76405

4.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76405?

In the Splunk On-Call (VictorOps) application, versions preceding 1.0.43 contain a vulnerability that allows users without 'admin' or 'power' roles to access a partially obscured API key stored in the application's Key Value Store (KV Store). This exposure arises from the inadequate masking of the API key during storage, creating potential security risks for users and systems reliant on the proper handling of sensitive keys.

Affected Version(s)

Splunk On-Call (VictorOps) 1.0 < 1.0.43

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.