Medium severity4.3NVD Advisory· Published Oct 7, 2026
CVE-2026-76267
CVE-2026-76267
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could inject forged entries into the app log through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk App for Splunk O11y Cloud does not neutralize user-supplied SignalFlow content before writing it to the app log.
Splunk Enterprise versions 9.4.x are not affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <10.4.3, <10.2.7, <10.0.10
- Range: <10.4.3, <10.2.7, <10.0.10
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.