CVE-2026-76272 vulnerability in Splunk Products
Published on October 7, 2026
Missing Access Control through the REST API in Splunk Secure Gateway
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72 are also affected. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-76272 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-76272
stack.watch emails you whenever new vulnerabilities are published in Splunk or Splunk Secure Gateway. Just hit a watch button to start following.
Affected Versions
Splunk Enterprise:- Version 10.4 and below 10.4.3 is affected.
- Version 10.2 and below 10.2.7 is affected.
- Version 10.0 and below 10.0.10 is affected.
- Version 9.4 and below 9.4.15 is affected.
- Version 3.10 and below 3.10.11 is affected.
- Version 3.9 and below 3.9.25 is affected.
- Version 3.8 and below 3.8.72 is affected.