CVE-2026-76390
Last modified
CVE-2026-76390 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and authentication model. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and authentication model. The vulnerability is possible because the generated OpenAPI specification is packaged in a static file path that Splunk Web serves without authentication. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Talos Intelligence For Enterprise Security Cloud | >= 1.0.0, < 1.0.3 |
References
- https://advisory.splunk.com/advisories/SVD-2026-0808Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-76390?
How severe is CVE-2026-76390?
How do I fix CVE-2026-76390?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-76385In versions below 2.1.4 of the Venafi app for Splunk SOAR, a…4.3
- CVE-2026-76386In versions below 3.2.2 of the Zoom app for Splunk SOAR, a u…4.3
- CVE-2026-76387In Splunk Enterprise Security versions below 8.6.1, a user w…8.1
- CVE-2026-76388In Splunk Enterprise Security versions below 8.6.1, a user w…8.1
- CVE-2026-76389In Cisco Talos Intelligence for Enterprise Security Cloud ve…8.8
- CVE-2026-7639Software installed and run as a non-privileged user may cond…7.8
- CVE-2026-76391In Splunk AI Toolkit versions below 6.0.0, a user who does n…8.3
- CVE-2026-76392In Splunk AI Toolkit versions below 6.0.0, a user who does n…5.4
- CVE-2026-76393In Splunk AI Toolkit versions below 6.0.0, a user who can up…5.9
- CVE-2026-76394In Splunk AI Toolkit versions below 6.0.0, a low-privileged …8.3
- CVE-2026-76395In Splunk AI Toolkit versions below 6.0.0, a user who holds …8.8
- CVE-2026-76396In Splunk AI Toolkit versions below 6.0.0, a user that holds…7.5
Are you affected by CVE-2026-76390?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
