PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-76276 Splunk CVE debrief

A low-privileged user could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web in Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 due to embedded source maps in production JavaScript bundles. This vulnerability allows unauthorized access to sensitive app code, potentially exposing it to malicious actors. The affected versions of Splunk Enterprise have production JavaScript bundles that contain embedded source maps, which include original source code. This issue is particularly concerning for Splunk Enterprise administrators and users with access to the Discover Splunk Observability Cloud app, as they should assess their to

Vendor
Splunk
Product
Splunk Enterprise
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Splunk Enterprise administrators and users with access to the Discover Splunk Observability Cloud app should assess exposure and take remediation steps to prevent unauthorized access to sensitive app code.

Why it matters

Defenders should care about CVE-2026-76276 because it allows low-privileged users to retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web in affected Splunk Enterprise versions, potentially exposing sensitive app code.

  • Potential exposure of sensitive app code
  • Need to verify affected Splunk Enterprise versions
  • Requirement to restrict access to sensitive app code
  • Importance of monitoring for suspicious activity

Technical summary

The vulnerability is caused by embedded source maps in production JavaScript bundles for the Discover Splunk Observability Cloud app, allowing low-privileged users to retrieve original source code through Splunk Web in affected Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10. This issue arises because the production JavaScript bundles contain embedded source maps that include original source code, making it accessible to users with low privileges. The vulnerability has a CVSS score of 4.3 and a severity rating of MEDIUM. There is no evidence of public exploitation or specific victim organizations affected by this vulnerability.

Defensive priority

Defenders should prioritize verifying affected Splunk Enterprise versions and restricting access to sensitive app code.

Recommended defensive actions

  • Verify and update Splunk Enterprise to versions 10.4.3, 10.2.7, or 10.0.10
  • Restrict access to sensitive app code and configure role-based user access
  • Monitor for suspicious activity related to the Discover Splunk Observability Cloud app
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and potential impact. However, additional information on exploitation or victim organizations is not available. The vulnerability is caused by embedded source maps in production JavaScript bundles for the Discover Splunk Observability Cloud app, allowing low-privileged users to retrieve original source code through Splunk Web. There is no evidence of public exploitation or specific victim organizations affected by this vulnerability. Defenders can

Sources and references

Verified primary and authoritative sources

  • CVE-2026-76276 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-76276

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-76276 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76276

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.