PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76265 Splunk CVE debrief

CVE-2026-76265 Improper Access Control through REST API Endpoints in Splunk Secure Gateway. A user without 'admin' or 'power' Splunk roles could access privileged Splunk Secure Gateway functionality, potentially causing it to sign attacker-controlled payloads. This issue affects Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Splunk Enterprise and Splunk Secure Gateway administrators and security teams should assess exposure and prioritize remediation efforts, especially in deployments with less restrictive user access controls. They should verify Splunk Enterprise and Splunk Secure Gateway versions against the affected versions list and restrict access to Splunk Secure Gateway functionality based on user roles.

Why it matters

CVE-2026-76265 allows unauthorized access to privileged Splunk Secure Gateway functionality, potentially enabling attackers to sign malicious payloads. Defenders should verify exposure, especially in deployments with less restrictive user access controls, and prioritize remediation for affected versions.

  • Potential unauthorized access to privileged Splunk Secure Gateway functionality.
  • Possible signing of attacker-controlled payloads by Splunk Secure Gateway.
  • Verification of user access controls and role-based access restrictions is necessary.
  • Remediation priority for affected Splunk Enterprise and Splunk Secure Gateway versions.

Technical summary

The vulnerability exists in multiple Splunk Secure Gateway REST API endpoints that do not enforce authorization requirements, allowing users without 'admin' or 'power' roles to access privileged functionality and potentially sign attacker-controlled payloads. This issue affects Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72. Defenders should prioritize verifying exposure in Splunk Enterprise and Splunk Secure Gateway deployments, especially where user access controls are not strictly enforced.

Defensive priority

Defenders should prioritize verifying exposure in Splunk Enterprise and Splunk Secure Gateway deployments, especially where user access controls are not strictly enforced.

Recommended defensive actions

  • Verify Splunk Enterprise and Splunk Secure Gateway versions against the affected versions list.
  • Restrict access to Splunk Secure Gateway functionality based on user roles.
  • Monitor for unusual activity related to Splunk Secure Gateway payload signing.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and source item provide details on the vulnerability in Splunk Secure Gateway, including affected versions and potential impacts. Defenders should verify exposure, especially in deployments with less restrictive user access controls, and prioritize remediation for affected versions. The vulnerability exists in multiple Splunk Secure Gateway REST API endpoints that do not enforce authorization requirements, allowing users without 'admin' or 'power' roles to access privileged functionality and potentially sign attacker-

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76265 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76265

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76265 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76265

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.