Splunk Secure Gateway Privileged Access via Unchecked REST API (v<10.4.3)
CVE-2026-76265 Published on October 7, 2026

Improper Access Control through REST API Endpoints in Splunk Secure Gateway
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.

NVD

Weakness Type

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-76265 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-76265

stack.watch emails you whenever new vulnerabilities are published in Splunk or Splunk Secure Gateway. Just hit a watch button to start following.

 
 

Affected Versions

Splunk Enterprise: Splunk Secure Gateway: