Get real-time updates on Telegram
Verified
CVE-2026-76278: Splunk Enterprise 10.4 to before 10.4.3, 10.2 to before 10.2.7, 10.0 to before 10.0.10
Affected technology
Splunk Enterprise · 10.4 to before 10.4.3, 10.2 to before 10.2.7, 10.0 to before 10.0.10
Splunk
Description’s affected range: versions below 10.4.3
Component: REST API
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. Vendor/CNA’s CVSS 3.1 assessment (base score 4.3/10) rates confidentiality impact as low; integrity and availability impact as none.
- CWE
- CWE-639
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-76278.html