{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-76274", "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633", "state": "PUBLISHED", "assignerShortName": "cisco", "dateReserved": "2026-08-19T12:02:03.620Z", "datePublished": "2026-10-07T20:46:34.443Z", "dateUpdated": "2026-10-07T20:46:34.443Z" }, "containers": { "cna": { "affected": [ { "product": "Splunk Enterprise", "vendor": "Splunk", "versions": [ { "version": "10.4", "status": "affected", "versionType": "custom", "lessThan": "10.4.3" }, { "version": "10.2", "status": "affected", "versionType": "custom", "lessThan": "10.2.7" }, { "version": "10.0", "status": "affected", "versionType": "custom", "lessThan": "10.0.10" } ], "modules": [ "REST API" ] } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/markdown", "value": "In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the `read_o11y_content` capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see [Authentication tokens](https://help.splunk.com/en/splunk-observability-cloud/administer/authentication-and-security/authentication-tokens) in the Splunk documentation.\n\nSplunk Enterprise versions 9.4.x are not affected." } ], "value": "In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens (https://help.splunk.com/en/splunk-observability-cloud/administer/authentication-and-security/authentication-tokens) in the Splunk documentation.\n\nSplunk Enterprise versions 9.4.x are not affected." } ], "references": [ { "url": "https://advisory.splunk.com/advisories/SVD-2026-1001" } ], "title": "Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observability Cloud", "datePublic": "2026-10-07T00:00:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "type": "cwe", "cweId": "CWE-918", "description": "The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination." } ] } ], "source": { "advisory": "SVD-2026-1001", "discovery": "INTERNAL" }, "providerMetadata": { "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633", "shortName": "cisco", "dateUpdated": "2026-10-07T20:46:34.443Z" }, "metrics": [ { "cvssV3_1": { "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1", "baseScore": 6.5, "baseSeverity": "MEDIUM" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "solutions": [ { "lang": "en", "value": "Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher." } ], "workarounds": [ { "lang": "en", "value": "Turn off or remove the Splunk App for Splunk Observability Cloud. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation." } ], "credits": [ { "lang": "en", "value": "Gabriel Nitu, Splunk", "type": "finder" } ] } } }