PatchSiren cyber security CVE debrief
CVE-2026-76265 Splunk CVE debrief
CVE-2026-76265 Improper Access Control through REST API Endpoints in Splunk Secure Gateway. A user without 'admin' or 'power' Splunk roles could access privileged Splunk Secure Gateway functionality, potentially causing it to sign attacker-controlled payloads. This issue affects Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Splunk Enterprise and Splunk Secure Gateway administrators and security teams should assess exposure and prioritize remediation efforts, especially in deployments with less restrictive user access controls. They should verify Splunk Enterprise and Splunk Secure Gateway versions against the affected versions list and restrict access to Splunk Secure Gateway functionality based on user roles.
Why it matters
CVE-2026-76265 allows unauthorized access to privileged Splunk Secure Gateway functionality, potentially enabling attackers to sign malicious payloads. Defenders should verify exposure, especially in deployments with less restrictive user access controls, and prioritize remediation for affected versions.
- Potential unauthorized access to privileged Splunk Secure Gateway functionality.
- Possible signing of attacker-controlled payloads by Splunk Secure Gateway.
- Verification of user access controls and role-based access restrictions is necessary.
- Remediation priority for affected Splunk Enterprise and Splunk Secure Gateway versions.
Technical summary
The vulnerability exists in multiple Splunk Secure Gateway REST API endpoints that do not enforce authorization requirements, allowing users without 'admin' or 'power' roles to access privileged functionality and potentially sign attacker-controlled payloads. This issue affects Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72. Defenders should prioritize verifying exposure in Splunk Enterprise and Splunk Secure Gateway deployments, especially where user access controls are not strictly enforced.
Defensive priority
Defenders should prioritize verifying exposure in Splunk Enterprise and Splunk Secure Gateway deployments, especially where user access controls are not strictly enforced.
Recommended defensive actions
- Verify Splunk Enterprise and Splunk Secure Gateway versions against the affected versions list.
- Restrict access to Splunk Secure Gateway functionality based on user roles.
- Monitor for unusual activity related to Splunk Secure Gateway payload signing.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability in Splunk Secure Gateway, including affected versions and potential impacts. Defenders should verify exposure, especially in deployments with less restrictive user access controls, and prioritize remediation for affected versions. The vulnerability exists in multiple Splunk Secure Gateway REST API endpoints that do not enforce authorization requirements, allowing users without 'admin' or 'power' roles to access privileged functionality and potentially sign attacker-
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76265 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76265
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76265 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76265
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Improper Access Control through REST API Endpoints in Splunk Secure Gateway
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/76xxx/CVE-2026-76265.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-1001
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.