Medium severity4.3NVD Advisory· Published Aug 19, 2026· Updated Aug 26, 2026
CVE-2026-76256
CVE-2026-76256
Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read sensitive Security Assertion Markup Language setup and instance settings information through Splunk Secure Gateway Representational State Transfer (REST) API endpoints. The vulnerability is possible because the affected Security Assertion Markup Language setup and instance settings REST API endpoints do not enforce authorization requirements before returning configuration information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <10.4.2, <10.2.6, <10.0.9, <9.4.14
- Range: <3.10.9, <3.9.23, <3.8.70
Patches
Vulnerability mechanics
References
1- advisory.splunk.com/advisories/SVD-2026-0801nvdVendor Advisory
News mentions
0No linked articles in our index yet.