Splunk Secure Gateway REST API Config Disclosure before 10.4.2 & 3.10.9
CVE-2026-76256 Published on August 19, 2026
Information Exposure through REST API Endpoints in Splunk Secure Gateway
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup Language setup and instance settings information through Splunk Secure Gateway Representational State Transfer (REST) API endpoints. The vulnerability is possible because the affected Security Assertion Markup Language setup and instance settings REST API endpoints do not enforce authorization requirements before returning configuration information.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-76256 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-76256
stack.watch emails you whenever new vulnerabilities are published in Splunk or Splunk Secure Gateway. Just hit a watch button to start following.
Affected Versions
Splunk Enterprise:- Version 10.4 and below 10.4.2 is affected.
- Version 10.2 and below 10.2.6 is affected.
- Version 10.0 and below 10.0.9 is affected.
- Version 9.4 and below 9.4.14 is affected.
- Version 3.10 and below 3.10.9 is affected.
- Version 3.9 and below 3.9.23 is affected.
- Version 3.8 and below 3.8.70 is affected.