CVE-2026-76405
Last modified
CVE-2026-76405 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/administer-the-app-key-value-store/about-the-app-key-value-store) in the Splunk documentation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Splunk | On-Call | < 1.0.43 |
References
- https://advisory.splunk.com/advisories/SVD-2026-0808Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-76405?
How severe is CVE-2026-76405?
How do I fix CVE-2026-76405?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7640The WP Customer Area plugin for WordPress is vulnerable to S…6.4
- CVE-2026-76400In Splunk Connect for Kafka versions below 2.2.7, an unauthe…5.9
- CVE-2026-76401In Splunk Connect for Kafka versions below 2.2.7, an unauthe…5.9
- CVE-2026-76402In Splunk Connect for Kafka versions below 2.2.7, an unauthe…8.2
- CVE-2026-76403In Splunk Connect for Kafka versions below 2.2.7, an unauthe…7.4
- CVE-2026-76404In Splunk MCP Server app versions below 1.2.1, a user who ho…9.1
- CVE-2026-7641The Import and export users and customers plugin for WordPre…8.8
- CVE-2026-7642A vulnerability was detected in pskill9 website-downloader u…6.3
- CVE-2026-7643A flaw has been found in ChatGPTNextWeb NextChat up to 2.16.…4.3
- CVE-2026-7644A vulnerability has been found in ChatGPTNextWeb NextChat up…7.3
- CVE-2026-76440As part of Cisco's ongoing commitment to proactive security …9.8
- CVE-2026-76441As part of Cisco's ongoing commitment to proactive security …9.8
Are you affected by CVE-2026-76405?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
