4.3
CVE-2026-76256
- EPSS 0.22%
- Veröffentlicht 19.08.2026 21:34:15
- Zuletzt bearbeitet 20.08.2026 14:54:14
- CVE-Watchlists
- Unerledigt
Information Exposure through REST API Endpoints in Splunk Secure Gateway
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup Language setup and instance settings information through Splunk Secure Gateway Representational State Transfer (REST) API endpoints. The vulnerability is possible because the affected Security Assertion Markup Language setup and instance settings REST API endpoints do not enforce authorization requirements before returning configuration information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Splunk ≫ Splunk Secure Gateway Version >= 3.8.0 < 3.8.70
Splunk ≫ Splunk Secure Gateway Version >= 3.9.0 < 3.9.23
Splunk ≫ Splunk Secure Gateway Version >= 3.10.0 < 3.10.9
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.133 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Cisco PSIRT | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://advisory.splunk.com/advisories/SVD-2026-0801