CVE-2026-76272
Last modified
CVE-2026-76272 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72 are also affected. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk Enterprise | >= 10.4, < 10.4.3; >= 10.2, < 10.2.7; >= 10.0, < 10.0.10; >= 9.4, < 9.4.15 |
| Splunk | Splunk Secure Gateway | >= 3.10, < 3.10.11; >= 3.9, < 3.9.25; >= 3.8, < 3.8.72 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-76272?
How severe is CVE-2026-76272?
How do I fix CVE-2026-76272?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76267In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…4.3
- CVE-2026-76268In Splunk Enterprise versions below 10.4.3 and 10.2.7, an un…9.8
- CVE-2026-76269In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…6.5
- CVE-2026-7627A security vulnerability has been detected in 8nite metatrad…6.3
- CVE-2026-76270In Splunk Enterprise versions below 10.4.3, a user that hold…6.5
- CVE-2026-76271In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…6.5
- CVE-2026-76273In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…4.3
- CVE-2026-76274In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…6.5
- CVE-2026-76275In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…4.3
- CVE-2026-76276In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…4.3
- CVE-2026-76277In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10,…4.1
- CVE-2026-76278In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0…4.3
Are you affected by CVE-2026-76272?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
