Splunk Enterprise API Data Exposure via Unrestricted Job Listings <10.4.3
CVE-2026-76275 Published on October 7, 2026
Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search query text and job metadata for jobs that belong to other users, including job identifiers, dispatch parameters, result counts, and execution metadata, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully enforce per-user authorization before it includes job information in search job listings.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-76275 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-76275
Want to know whenever a new CVE is published for Splunk? stack.watch will email you.
Affected Versions
Splunk Enterprise:- Version 10.4 and below 10.4.3 is affected.
- Version 10.2 and below 10.2.7 is affected.
- Version 10.0 and below 10.0.10 is affected.
- Version 9.4 and below 9.4.15 is affected.