CVE-2026-76272: Splunk Enterprise

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72 are also affected. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.

Affected products

  • Splunk Splunk Enterprise: from 10.4, before 10.4.3 (fixed in 10.4.3); from 10.2, before 10.2.7 (fixed in 10.2.7); from 10.0, before 10.0.10 (fixed in 10.0.10); from 9.4, before 9.4.15 (fixed in 9.4.15)
  • Splunk Splunk Secure Gateway: from 3.10, before 3.10.11 (fixed in 3.10.11); from 3.9, before 3.9.25 (fixed in 3.9.25); from 3.8, before 3.8.72 (fixed in 3.8.72)

Published 2026-10-07. Last modified 2026-10-08.