CVE-2026-76389Disclosure(cisco / talos_intelligence_for_enterprise_security_cloud)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the instance to make an outbound request to an attacker-controlled server. The request could expose tokens that compromise all relevant data and system integrity in the Splunk instance. The vulnerability is possible because the Talos intelligence enrichment REST endpoint accepts the destination for authenticated Splunk management requests from request data. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • talos_intelligence_for_enterprise_security_cloud

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
talos_intelligence_for_enterprise_security_cloud

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1Technical Details · 2026-08-19: 108-1908-20
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-191
Disclosure1
2026-08-201
General1
Full discourse2 posts
  • SecureShield@SecureShield_
    General

    一次情報(NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-76389 参照元(ベンダー等): https://advisory.splunk.com/advisories/SVD-2026-0808

    Post summary

    The post merely links to the NVD entry and vendor advisory for CVE‑2026‑76389, providing no further detail or actionable information.

    0000067
    26 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-76389 In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_t… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-76389 #Cisco #CyberSecurity #InfoSec

    Post summary

    High‑severity CVE‑2026‑76389 affecting Cisco Talos Enterprise Security Cloud (versions <1.0.3) has been disclosed with a CVSS score of 8.8; no PoC, exploit, or patch details are provided in the snippet.

    0000082
    82 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscotalos_intelligence_for_enterprise_security_cloud---

Explore more