Splunk Secure Gateway REST API Config Disclosure before 10.4.2 & 3.10.9
CVE-2026-76256 Published on August 19, 2026

Information Exposure through REST API Endpoints in Splunk Secure Gateway
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup Language setup and instance settings information through Splunk Secure Gateway Representational State Transfer (REST) API endpoints. The vulnerability is possible because the affected Security Assertion Markup Language setup and instance settings REST API endpoints do not enforce authorization requirements before returning configuration information.

NVD

Weakness Type

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-76256 has been classified to as an Information Disclosure vulnerability or weakness.


Products Associated with CVE-2026-76256

stack.watch emails you whenever new vulnerabilities are published in Splunk or Splunk Secure Gateway. Just hit a watch button to start following.

 
 

Affected Versions

Splunk Enterprise: Splunk Secure Gateway: