CVE-2026-76265
CVE-2026-76265: 1 tracked advisory record across Splunk. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Splunk
1 advisory- Advisory severityMedium6.5
Medium [CVE-2026-76265] Improper Access Control through REST API Endpoints in Splunk Secure Gateway
CVE-2026-76265Source published Source updated
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the "admin" or "power" Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.
- Affected products in this advisory
- Splunk Enterprise
- Splunk Secure Gateway
- Source-reported affected versions
- Splunk Enterprise 10.4 before 10.4.3
- Splunk Enterprise 10.2 before 10.2.7
- Splunk Enterprise 10.0 before 10.0.10
- Splunk Enterprise 9.4 before 9.4.15
3 more entries in the full advisory.
- Source-reported fixed versions
- 10.4.3
- 10.2.7
- 10.0.10
- 9.4.15
3 more entries in the full advisory.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Splunk CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.