PatchSiren cyber security CVE debrief
CVE-2026-76272 Splunk CVE debrief
A vulnerability in Splunk Secure Gateway allows an attacker to cause the gateway to sign attacker-controlled payloads due to missing access control. This issue affects Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, as well as Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72. The vulnerability could allow an attacker to sign and use malicious payloads within the Splunk environment, potentially leading to unauthorized actions. Defenders should prioritize verifying affected versions, applying updates, and reviewing access controls to prevent exploitation.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for managing Splunk Enterprise and Splunk Secure Gateway installations should assess their environment for potential exposure and apply necessary updates. This includes reviewing user roles and ensuring that access controls are properly configured.
Why it matters
This vulnerability in Splunk Secure Gateway could allow an attacker to sign and use malicious payloads within the Splunk environment, potentially leading to unauthorized actions. Defenders should prioritize verifying affected versions, applying updates, and reviewing access controls to prevent exploitation.
- Defenders need to verify the versions of Splunk Enterprise and Splunk Secure Gateway in their environment to determine potential exposure.
- Applying updates to affected versions is crucial to prevent potential exploitation.
- Reviewing and updating user roles and capabilities in Splunk can help prevent unauthorized access to sensitive features.
- Defenders should monitor for any suspicious activity related to Splunk Secure Gateway and REST API usage.
Technical summary
The vulnerability is caused by a lack of access control in Splunk Secure Gateway, allowing users without 'admin' or 'power' roles to request signatures for attacker-controlled payloads. This could potentially allow an attacker to sign and use malicious payloads within the Splunk environment. The affected versions of Splunk Enterprise and Splunk Secure Gateway are specified in the CVE record. Defenders should prioritize verifying the affected versions of Splunk Enterprise and Splunk Secure Gateway in their environment, and applying the necessary updates to prevent potential exploitation.
Defensive priority
Defenders should prioritize verifying the affected versions of Splunk Enterprise and Splunk Secure Gateway in their environment, and applying the necessary updates to prevent potential exploitation.
Recommended defensive actions
- Verify the versions of Splunk Enterprise and Splunk Secure Gateway in your environment against the affected versions listed in the CVE record.
- Apply the necessary updates to Splunk Enterprise and Splunk Secure Gateway to prevent potential exploitation.
- Review and update roles and capabilities in Splunk to ensure that users do not have unauthorized access to sensitive features.
- Monitor for any suspicious activity related to Splunk Secure Gateway and REST API usage.
- Perform an inventory of assets using Splunk Enterprise and Splunk Secure Gateway to identify potential exposure.
- Review change management processes to ensure that updates can be applied in a timely manner.
- Track and document the verification and remediation of affected systems.
Evidence notes
The vulnerability is caused by a lack of access control in Splunk Secure Gateway, allowing users without 'admin' or 'power' roles to request signatures for attacker-controlled payloads. The affected versions of Splunk Enterprise and Splunk Secure Gateway are specified in the CVE record.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76272 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76272
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76272 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76272
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Missing Access Control through the REST API in Splunk Secure Gateway
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/76xxx/CVE-2026-76272.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-1001
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.