CYBER CODE RED

Get real-time updates on Telegram

Verified

CVE-2026-76278: Splunk Enterprise 10.4 to before 10.4.3, 10.2 to before 10.2.7, 10.0 to before 10.0.10

Affected technology

Splunk Enterprise · 10.4 to before 10.4.3, 10.2 to before 10.2.7, 10.0 to before 10.0.10
Splunk

Description’s affected range: versions below 10.4.3

Component: REST API

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. Vendor/CNA’s CVSS 3.1 assessment (base score 4.3/10) rates confidentiality impact as low; integrity and availability impact as none.

Published

CWE
CWE-639
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-76278.html