{"api_version":"1","generated_at":"2026-10-10T01:51:47+00:00","cve":"CVE-2026-76280","urls":{"html":"https://cve.report/CVE-2026-76280","api":"https://cve.report/api/cve/CVE-2026-76280.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-76280","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-76280"},"summary":{"title":"Incorrect Permission Assignment for App Key Value Store Collections in Splunk Secure Gateway","description":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the \"admin\" or \"sc_admin\" Splunk roles could modify Splunk Secure Gateway alert and mobile-device recipient data in App Key Value Store (KV Store) collections that later alert and subscription workflows use. The vulnerability is possible because the affected collections allow unrestricted write access instead of limiting writes to authorized Splunk Secure Gateway workflows. For more information see About the app key value store (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/administer-the-app-key-value-store/about-the-app-key-value-store), KV store endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.4/kv-store-endpoints/kv-store-endpoint-descriptions), and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.","state":"PUBLISHED","assigner":"cisco","published_at":"2026-10-07 21:17:19","updated_at":"2026-10-09 17:16:49"},"problem_types":["CWE-732","CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors."],"metrics":[{"version":"3.1","source":"psirt@cisco.com","type":"Secondary","score":"6.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"6.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","data":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001","name":"https://advisory.splunk.com/advisories/SVD-2026-1001","refsource":"psirt@cisco.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76280","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76280","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Splunk","product":"Splunk Enterprise","version":"affected 10.4 10.4.3 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Enterprise","version":"affected 10.2 10.2.7 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Enterprise","version":"affected 10.0 10.0.10 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Enterprise","version":"affected 9.4 9.4.15 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Secure Gateway","version":"affected 3.10 3.10.11 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Secure Gateway","version":"affected 3.9 3.9.25 custom","platforms":[]},{"source":"CNA","vendor":"Splunk","product":"Splunk Secure Gateway","version":"affected 3.8 3.8.72 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.\n\nUpgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"M Mahdan Argya Syarif (0xbeludan)","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"76280","cve":"CVE-2026-76280","epss":"0.001700000","percentile":"0.057790000","score_date":"2026-10-09","updated_at":"2026-10-10 00:07:02"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-76280","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-09T16:15:39.990544Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-09T16:47:52.058Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"modules":["REST API"],"product":"Splunk Enterprise","vendor":"Splunk","versions":[{"lessThan":"10.4.3","status":"affected","version":"10.4","versionType":"custom"},{"lessThan":"10.2.7","status":"affected","version":"10.2","versionType":"custom"},{"lessThan":"10.0.10","status":"affected","version":"10.0","versionType":"custom"},{"lessThan":"9.4.15","status":"affected","version":"9.4","versionType":"custom"}]},{"product":"Splunk Secure Gateway","vendor":"Splunk","versions":[{"lessThan":"3.10.11","status":"affected","version":"3.10","versionType":"custom"},{"lessThan":"3.9.25","status":"affected","version":"3.9","versionType":"custom"},{"lessThan":"3.8.72","status":"affected","version":"3.8","versionType":"custom"}]}],"credits":[{"lang":"en","type":"reporter","value":"M Mahdan Argya Syarif (0xbeludan)"}],"datePublic":"2026-10-07T00:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/markdown","value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the \"admin\" or \"sc_admin\" Splunk roles could modify Splunk Secure Gateway alert and mobile-device recipient data in App Key Value Store (KV Store) collections that later alert and subscription workflows use. The vulnerability is possible because the affected collections allow unrestricted write access instead of limiting writes to authorized Splunk Secure Gateway workflows. For more information see [About the app key value store](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/administer-the-app-key-value-store/about-the-app-key-value-store), [KV store endpoint descriptions](https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.4/kv-store-endpoints/kv-store-endpoint-descriptions), and [About configuring role-based user access](https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation."}],"value":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the \"admin\" or \"sc_admin\" Splunk roles could modify Splunk Secure Gateway alert and mobile-device recipient data in App Key Value Store (KV Store) collections that later alert and subscription workflows use. The vulnerability is possible because the affected collections allow unrestricted write access instead of limiting writes to authorized Splunk Secure Gateway workflows. For more information see About the app key value store (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/administer-the-app-key-value-store/about-the-app-key-value-store), KV store endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.4/kv-store-endpoints/kv-store-endpoint-descriptions), and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation."}],"metrics":[{"cvssV3_1":{"baseScore":6.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-732","description":"The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.","lang":"en","type":"cwe"}]}],"providerMetadata":{"dateUpdated":"2026-10-07T20:46:37.327Z","orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco"},"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-1001"}],"solutions":[{"lang":"en","value":"Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.\n\nUpgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher."}],"source":{"advisory":"SVD-2026-1001","discovery":""},"title":"Incorrect Permission Assignment for App Key Value Store Collections in Splunk Secure Gateway","workarounds":[{"lang":"en","value":"Turn off or remove the Splunk Secure Gateway app. See [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app."}]}},"cveMetadata":{"assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","assignerShortName":"cisco","cveId":"CVE-2026-76280","datePublished":"2026-10-07T20:46:37.327Z","dateReserved":"2026-08-19T12:02:03.621Z","dateUpdated":"2026-10-09T16:47:52.058Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-07 21:17:19","lastModifiedDate":"2026-10-09 17:16:49","problem_types":["CWE-732","CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors."],"metrics":{"cvssMetricV31":[{"source":"psirt@cisco.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","baseScore":6.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":3.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-09T16:15:39.990544Z","id":"CVE-2026-76280","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"76280","Ordinal":"1","Title":"Incorrect Permission Assignment for App Key Value Store Collecti","CVE":"CVE-2026-76280","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"76280","Ordinal":"1","NoteData":"In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the \"admin\" or \"sc_admin\" Splunk roles could modify Splunk Secure Gateway alert and mobile-device recipient data in App Key Value Store (KV Store) collections that later alert and subscription workflows use. The vulnerability is possible because the affected collections allow unrestricted write access instead of limiting writes to authorized Splunk Secure Gateway workflows. For more information see About the app key value store (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/administer-the-app-key-value-store/about-the-app-key-value-store), KV store endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.4/kv-store-endpoints/kv-store-endpoint-descriptions), and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.","Type":"Description","Title":"Incorrect Permission Assignment for App Key Value Store Collecti"}]}}}