CVE-2026-76272
Reported by cisco · Published October 7, 2026
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72 are also affected. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk Enterprise | 10.4, 10.2, 10.0 |
| Splunk | Splunk Secure Gateway | 3.10, 3.9, 3.8 |
| Splunk | Splunk Secure Gateway | 3.10, 3.9, 3.8 |
| Splunk | Splunk Enterprise | 10.0, 10.4, 9.4 |
Timeline
- Oct 7, 2026 CVE Published
- Oct 8, 2026 EPSS Score
- Oct 8, 2026 CVE Updated