PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76272 Splunk CVE debrief

A vulnerability in Splunk Secure Gateway allows an attacker to cause the gateway to sign attacker-controlled payloads due to missing access control. This issue affects Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, as well as Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72. The vulnerability could allow an attacker to sign and use malicious payloads within the Splunk environment, potentially leading to unauthorized actions. Defenders should prioritize verifying affected versions, applying updates, and reviewing access controls to prevent exploitation.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for managing Splunk Enterprise and Splunk Secure Gateway installations should assess their environment for potential exposure and apply necessary updates. This includes reviewing user roles and ensuring that access controls are properly configured.

Why it matters

This vulnerability in Splunk Secure Gateway could allow an attacker to sign and use malicious payloads within the Splunk environment, potentially leading to unauthorized actions. Defenders should prioritize verifying affected versions, applying updates, and reviewing access controls to prevent exploitation.

  • Defenders need to verify the versions of Splunk Enterprise and Splunk Secure Gateway in their environment to determine potential exposure.
  • Applying updates to affected versions is crucial to prevent potential exploitation.
  • Reviewing and updating user roles and capabilities in Splunk can help prevent unauthorized access to sensitive features.
  • Defenders should monitor for any suspicious activity related to Splunk Secure Gateway and REST API usage.

Technical summary

The vulnerability is caused by a lack of access control in Splunk Secure Gateway, allowing users without 'admin' or 'power' roles to request signatures for attacker-controlled payloads. This could potentially allow an attacker to sign and use malicious payloads within the Splunk environment. The affected versions of Splunk Enterprise and Splunk Secure Gateway are specified in the CVE record. Defenders should prioritize verifying the affected versions of Splunk Enterprise and Splunk Secure Gateway in their environment, and applying the necessary updates to prevent potential exploitation.

Defensive priority

Defenders should prioritize verifying the affected versions of Splunk Enterprise and Splunk Secure Gateway in their environment, and applying the necessary updates to prevent potential exploitation.

Recommended defensive actions

  • Verify the versions of Splunk Enterprise and Splunk Secure Gateway in your environment against the affected versions listed in the CVE record.
  • Apply the necessary updates to Splunk Enterprise and Splunk Secure Gateway to prevent potential exploitation.
  • Review and update roles and capabilities in Splunk to ensure that users do not have unauthorized access to sensitive features.
  • Monitor for any suspicious activity related to Splunk Secure Gateway and REST API usage.
  • Perform an inventory of assets using Splunk Enterprise and Splunk Secure Gateway to identify potential exposure.
  • Review change management processes to ensure that updates can be applied in a timely manner.
  • Track and document the verification and remediation of affected systems.

Evidence notes

The vulnerability is caused by a lack of access control in Splunk Secure Gateway, allowing users without 'admin' or 'power' roles to request signatures for attacker-controlled payloads. The affected versions of Splunk Enterprise and Splunk Secure Gateway are specified in the CVE record.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76272 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76272

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76272 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76272

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.