CVE-2026-76340
Reported by cisco · Published August 19, 2026
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. The vulnerability does not affect Splunk Enterprise versions below 10.4. The vulnerability is possible because the REST API does not require authentication or the change_authentication capability for the token-key reload action. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk Enterprise | 10.4 |
| Splunk | Splunk Enterprise | 10.4, 10.4 |
Timeline
- Aug 19, 2026 CVE Published
- Aug 20, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 CVE Updated