4.3
CVE-2026-76275
- EPSS -
- Veröffentlicht 07.10.2026 20:46:34
- Zuletzt bearbeitet 07.10.2026 21:17:18
- Erkennungen
Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the "admin" or "power" Splunk roles could access search query text and job metadata for jobs that belong to other users, including job identifiers, dispatch parameters, result counts, and execution metadata, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully enforce per-user authorization before it includes job information in search job listings.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSplunk
≫
Produkt
Splunk Enterprise
Version
10.4
Version <
10.4.3
Status
affected
Version
10.2
Version <
10.2.7
Status
affected
Version
10.0
Version <
10.0.10
Status
affected
Version
9.4
Version <
9.4.15
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Cisco PSIRT | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
https://advisory.splunk.com/advisories/SVD-2026-1001