{"api_version":"1","generated_at":"2026-10-10T01:52:01+00:00","cve":"CVE-2026-76265","urls":{"html":"https://cve.report/CVE-2026-76265","api":"https://cve.report/api/cve/CVE-2026-76265.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-76265","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-76265"},"summary":{"title":"Improper Access Control through REST API Endpoints in Splunk Secure Gateway","description":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the \"admin\" or \"power\" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.","state":"PUBLISHED","assigner":"cisco","published_at":"2026-10-07 21:17:17","updated_at":"2026-10-09 17:16:48"},"problem_types":["CWE-284","CWE-284 The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor."],"metrics":[{"version":"3.1","source":"psirt@cisco.com","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001","name":"https://advisory.splunk.com/advisories/SVD-2026-1001","refsource":"psirt@cisco.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76265","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76265","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Splunk","product":"Splunk Enterprise","version":"affected 10.4 10.4.3 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Enterprise","version":"affected 10.2 10.2.7 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Enterprise","version":"affected 10.0 10.0.10 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Enterprise","version":"affected 9.4 9.4.15 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Secure Gateway","version":"affected 3.10 3.10.11 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Secure Gateway","version":"affected 3.9 3.9.25 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Secure Gateway","version":"affected 3.8 3.8.72 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.\n\nUpgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Younes Zendour (m3l4n0ff)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"76265","cve":"CVE-2026-76265","epss":"0.002340000","percentile":"0.131910000","score_date":"2026-10-09","updated_at":"2026-10-10 00:07:02"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-76265","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-09T16:15:44.810336Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-09T16:48:13.063Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"modules":["REST API"],"product":"Splunk Enterprise","vendor":"Splunk","versions":[{"lessThan":"10.4.3","status":"affected","version":"10.4","versionType":"custom"},{"lessThan":"10.2.7","status":"affected","version":"10.2","versionType":"custom"},{"lessThan":"10.0.10","status":"affected","version":"10.0","versionType":"custom"},{"lessThan":"9.4.15","status":"affected","version":"9.4","versionType":"custom"}]},{"modules":["REST API"],"product":"Splunk Secure Gateway","vendor":"Splunk","versions":[{"lessThan":"3.10.11","status":"affected","version":"3.10","versionType":"custom"},{"lessThan":"3.9.25","status":"affected","version":"3.9","versionType":"custom"},{"lessThan":"3.8.72","status":"affected","version":"3.8","versionType":"custom"}]}],"credits":[{"lang":"en","type":"reporter","value":"Younes Zendour (m3l4n0ff)"}],"datePublic":"2026-10-07T00:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/markdown","value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the \"admin\" or \"power\" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests."}],"value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the \"admin\" or \"power\" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests."}],"metrics":[{"cvssV3_1":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.","lang":"en","type":"cwe"}]}],"providerMetadata":{"dateUpdated":"2026-10-07T20:46:29.253Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001"}],"solutions":[{"lang":"en","value":"Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.\n\nUpgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher."}],"source":{"advisory":"SVD-2026-1001","discovery":""},"title":"Improper Access Control through REST API Endpoints in Splunk Secure Gateway","workarounds":[{"lang":"en","value":"Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app."}]}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2026-76265","datePublished":"2026-10-07T20:46:29.253Z","dateReserved":"2026-08-19T12:02:03.620Z","dateUpdated":"2026-10-09T16:48:13.063Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-07 21:17:17","lastModifiedDate":"2026-10-09 17:16:48","problem_types":["CWE-284","CWE-284 The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor."],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-09T16:15:44.810336Z","id":"CVE-2026-76265","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"76265","Ordinal":"1","Title":"Improper Access Control through REST API Endpoints in Splunk Sec","CVE":"CVE-2026-76265","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"76265","Ordinal":"1","NoteData":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the \"admin\" or \"power\" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.","Type":"Description","Title":"Improper Access Control through REST API Endpoints in Splunk Sec"}]}}}