CVE-2026-76251Patch(splunk / splunk)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk splunk systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk App for Splunk Observability Cloud to forward requests to Splunk Observability Cloud, including the Splunk Observability Cloud access token stored for the app. With this access, the user could view all relevant data available to that token and make limited changes to Splunk Observability Cloud content. The vulnerability does not affect Splunk Enterprise 9.4 and 9.3 versions. The vulnerability is possible because the app's Representational State Transfer (REST) API endpoint handlers do not enforce the read_o11y_content capability before forwarding requests with the stored access token. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
splunk

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-20: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-20: 108-20
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-76251 - Splunk Enterprise priv-esc. Non-admins can leak Observability Cloud tokens. CVSS 7.1. Patch now. #CVE #Splunk #infosec https://www.valtersit.com/cve/CVE-2026-76251/ #CVE #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #iceland #israel

    Post summary

    The announcement highlights a privileged escalation CVE in Splunk Enterprise with token leakage risk and a CVSS score of 7.1, and a patch is immediately available.

    00000114
    1.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---

Explore more