PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76274 Splunk CVE debrief

A Server-Side Request Forgery (SSRF) vulnerability exists in Splunk App for Splunk Observability Cloud, affecting Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10. A user with the read_o11y_content capability can redirect an outbound request through the REST API to an attacker-controlled host, disclosing the configured Observability Cloud API token. The vulnerability arises from insufficient validation of the destination of an outbound request.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Splunk Enterprise installations, particularly those using Splunk App for Splunk Observability Cloud, should assess their exposure and take necessary actions to prevent exploitation.

Why it matters

Defenders should care about this vulnerability as it can lead to the disclosure of sensitive API tokens and potential redirection of outbound requests to attacker-controlled hosts. They should verify the affected versions of Splunk Enterprise, restrict the read_o11y_content capability, and monitor for suspicious activity.

  • Potential disclosure of Observability Cloud API tokens
  • Possible redirection of outbound requests to attacker-controlled hosts
  • Need for verification of affected versions and mitigation of the vulnerability
  • Importance of monitoring for suspicious outbound requests

Technical summary

The vulnerability exists in Splunk App for Splunk Observability Cloud, affecting Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10. A user with the read_o11y_content capability can redirect an outbound request through the REST API to an attacker-controlled host, disclosing the configured Observability Cloud API token. This could lead to unauthorized access and potential security breaches. Defenders should prioritize verifying the affected versions of Splunk Enterprise and ensuring that the read_o11y_content capability is not exposed to untrusted users.

Defensive priority

Defenders should prioritize verifying the affected versions of Splunk Enterprise and ensuring that the read_o11y_content capability is not exposed to untrusted users. They should also monitor for any suspicious outbound requests from the Splunk App for Splunk Observability Cloud.

Recommended defensive actions

  • Verify the version of Splunk Enterprise and ensure it is not affected by the vulnerability
  • Restrict the read_o11y_content capability to trusted users
  • Monitor for suspicious outbound requests from the Splunk App for Splunk Observability Cloud
  • Consider implementing additional security measures to prevent SSRF attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details about the vulnerability, including its description, affected versions, and potential impact. However, there is limited information about the actual exploitation of the vulnerability or its consequences.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76274 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76274

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76274 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76274

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.