PatchSiren cyber security CVE debrief
CVE-2026-76276 Splunk CVE debrief
A low-privileged user could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web in Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10 due to embedded source maps in production JavaScript bundles. This vulnerability allows unauthorized access to sensitive app code, potentially exposing it to malicious actors. The affected versions of Splunk Enterprise have production JavaScript bundles that contain embedded source maps, which include original source code. This issue is particularly concerning for Splunk Enterprise administrators and users with access to the Discover Splunk Observability Cloud app, as they should assess their to
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Splunk Enterprise administrators and users with access to the Discover Splunk Observability Cloud app should assess exposure and take remediation steps to prevent unauthorized access to sensitive app code.
Why it matters
Defenders should care about CVE-2026-76276 because it allows low-privileged users to retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web in affected Splunk Enterprise versions, potentially exposing sensitive app code.
- Potential exposure of sensitive app code
- Need to verify affected Splunk Enterprise versions
- Requirement to restrict access to sensitive app code
- Importance of monitoring for suspicious activity
Technical summary
The vulnerability is caused by embedded source maps in production JavaScript bundles for the Discover Splunk Observability Cloud app, allowing low-privileged users to retrieve original source code through Splunk Web in affected Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10. This issue arises because the production JavaScript bundles contain embedded source maps that include original source code, making it accessible to users with low privileges. The vulnerability has a CVSS score of 4.3 and a severity rating of MEDIUM. There is no evidence of public exploitation or specific victim organizations affected by this vulnerability.
Defensive priority
Defenders should prioritize verifying affected Splunk Enterprise versions and restricting access to sensitive app code.
Recommended defensive actions
- Verify and update Splunk Enterprise to versions 10.4.3, 10.2.7, or 10.0.10
- Restrict access to sensitive app code and configure role-based user access
- Monitor for suspicious activity related to the Discover Splunk Observability Cloud app
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and potential impact. However, additional information on exploitation or victim organizations is not available. The vulnerability is caused by embedded source maps in production JavaScript bundles for the Discover Splunk Observability Cloud app, allowing low-privileged users to retrieve original source code through Splunk Web. There is no evidence of public exploitation or specific victim organizations affected by this vulnerability. Defenders can
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76276 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76276
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76276 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76276
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Information Disclosure in the Discover Splunk Observability Cloud app through Splunk Web for Spl
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/76xxx/CVE-2026-76276.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-1001
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.