CVE-2026-76261
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could read Spacebridge asymmetric private keys, which are secrets that compromise affected Spacebridge private-key material stored in the app collection, through the Splunk Secure Gateway App Key Value Store Representational State Transfer (REST) API. The vulnerability is possible on instances upgraded from older Splunk Secure Gateway deployments when the private-key migration remains incomplete, leaving key material in a collection with an insecure default access control list.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.21%
- CWE
- CWE-732
- Published
- 2026-08-19
- Last modified
- 2026-08-26
Affected products
- Splunk Splunk Enterprise
- Splunk Splunk Enterprise
- Splunk Splunk Enterprise
- Splunk Splunk Enterprise
- Splunk Splunk Secure Gateway
- Splunk Splunk Secure Gateway
- Splunk Splunk Secure Gateway
Weakness type
Related vulnerabilities
- CVE-2026-19583 — Velociraptor Required Permissions bypass by using client monitoring queries
- CVE-2026-79617 — Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
- CVE-2026-80054 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-82312 — OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated...
- CVE-2026-80112 — PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys
- CVE-2021-43613 — SysPasswordDxe: Password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
- CVE-2026-78604 — Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Privilege Escalation to SYSTEM
- CVE-2026-84806 — Kimai before 2.63.0 Authorization Bypass via Team Access Endpoints