5.4
CVE-2026-76347
- EPSS 0.21%
- Veröffentlicht 19.08.2026 21:34:43
- Zuletzt bearbeitet 20.08.2026 17:19:42
- CVE-Watchlists
- Unerledigt
Server-Side Request Forgery (SSRF) through the Report Notifications REST API in Splunk Secure Gateway
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSplunk
≫
Produkt
Splunk Enterprise
Version
10.4
Version <
10.4.2
Status
affected
Version
10.2
Version <
10.2.6
Status
affected
Version
10.0
Version <
10.0.9
Status
affected
Version
9.4
Version <
9.4.14
Status
affected
HerstellerSplunk
≫
Produkt
Splunk Secure Gateway
Version
3.10
Version <
3.10.9
Status
affected
Version
3.9
Version <
3.9.23
Status
affected
Version
3.8
Version <
3.8.70
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.114 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Cisco PSIRT | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://advisory.splunk.com/advisories/SVD-2026-0801