CVE-2026-76261
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Summary
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, which are secrets that compromise affected Spacebridge private-key material stored in the app collection, through the Splunk Secure Gateway App Key Value Store Representational State Transfer (REST) API. The vulnerability is possible on instances upgraded from older Splunk Secure Gateway deployments when the private-key migration remains incomplete, leaving key material in a collection with an insecure default access control list.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk Enterprise | 10.4 < 10.4.2 | affected |
| Splunk | Splunk Enterprise | 10.2 < 10.2.6 | affected |
| Splunk | Splunk Enterprise | 10.0 < 10.0.9 | affected |
| Splunk | Splunk Enterprise | 9.4 < 9.4.14 | affected |
| Splunk | Splunk Secure Gateway | 3.10 < 3.10.9 | affected |
| Splunk | Splunk Secure Gateway | 3.9 < 3.9.23 | affected |
| Splunk | Splunk Secure Gateway | 3.8 < 3.8.70 | affected |
Weaknesses
- CWE-732: The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Workarounds
Upgrade Splunk Secure Gateway to versions 3.10.9, 3.9.23, and 3.8.70, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See Manage app and add-on objects in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.