VDB
CVE-2026-76267
CVE-2026-76267
PUBLISHED
CVSS 4.3 MEDIUM
Reported by cisco · Published October 7, 2026
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could inject forged entries into the app log through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk App for Splunk O11y Cloud does not neutralize user-supplied SignalFlow content before writing it to the app log. Splunk Enterprise versions 9.4.x are not affected.
Risk Scores
CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk Enterprise | 10.4, 10.2, 10.0 |
| Splunk | Splunk Enterprise | 10.4, 10.2, 10.0 |
Timeline
- Oct 7, 2026 CVE Published
- Oct 8, 2026 EPSS Score
- Oct 8, 2026 CVE Updated