PatchSiren cyber security CVE debrief
CVE-2026-76274 Splunk CVE debrief
A Server-Side Request Forgery (SSRF) vulnerability exists in Splunk App for Splunk Observability Cloud, affecting Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10. A user with the read_o11y_content capability can redirect an outbound request through the REST API to an attacker-controlled host, disclosing the configured Observability Cloud API token. The vulnerability arises from insufficient validation of the destination of an outbound request.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Splunk Enterprise installations, particularly those using Splunk App for Splunk Observability Cloud, should assess their exposure and take necessary actions to prevent exploitation.
Why it matters
Defenders should care about this vulnerability as it can lead to the disclosure of sensitive API tokens and potential redirection of outbound requests to attacker-controlled hosts. They should verify the affected versions of Splunk Enterprise, restrict the read_o11y_content capability, and monitor for suspicious activity.
- Potential disclosure of Observability Cloud API tokens
- Possible redirection of outbound requests to attacker-controlled hosts
- Need for verification of affected versions and mitigation of the vulnerability
- Importance of monitoring for suspicious outbound requests
Technical summary
The vulnerability exists in Splunk App for Splunk Observability Cloud, affecting Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10. A user with the read_o11y_content capability can redirect an outbound request through the REST API to an attacker-controlled host, disclosing the configured Observability Cloud API token. This could lead to unauthorized access and potential security breaches. Defenders should prioritize verifying the affected versions of Splunk Enterprise and ensuring that the read_o11y_content capability is not exposed to untrusted users.
Defensive priority
Defenders should prioritize verifying the affected versions of Splunk Enterprise and ensuring that the read_o11y_content capability is not exposed to untrusted users. They should also monitor for any suspicious outbound requests from the Splunk App for Splunk Observability Cloud.
Recommended defensive actions
- Verify the version of Splunk Enterprise and ensure it is not affected by the vulnerability
- Restrict the read_o11y_content capability to trusted users
- Monitor for suspicious outbound requests from the Splunk App for Splunk Observability Cloud
- Consider implementing additional security measures to prevent SSRF attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details about the vulnerability, including its description, affected versions, and potential impact. However, there is limited information about the actual exploitation of the vulnerability or its consequences.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76274 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76274
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76274 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76274
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observability C
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/76xxx/CVE-2026-76274.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-1001
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.