CVE-2026-76347

MEDIUM CVSS 3.1: 5.4 EPSS 0.21%
Updated Aug 21, 2026
Splunk
Parameter Value
CVSS 5.4 (MEDIUM)
Affected Versions 10.0.0 — 9.4.14
Fixed In 9.4.14
Type CWE-918 (Server-Side Request Forgery (SSRF))
Vendor Splunk
Public PoC No

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a user who does not hold the "admin" or "power" Splunk roles could use Server-Side Request Forgery (SSRF) in report notifications to send system-authenticated requests to internal Splunk services, which could allow for changes to Search Head Cluster state and a denial of service. The vulnerability is possible because Splunk Secure Gateway does not validate report notification path values before it sends internal requests.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Vulnerable Products 7

Configuration From (including) Up to (excluding)
Splunk Splunk
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
9.4.0 9.4.14
Splunk Splunk
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
10.0.0 10.0.9
Splunk Splunk
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
10.2.0 10.2.6
Splunk Splunk
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
10.4.0 10.4.2
Splunk Splunk_Secure_Gateway
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
3.8.0 3.8.70
Splunk Splunk_Secure_Gateway
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
3.9.0 3.9.23
Splunk Splunk_Secure_Gateway
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
3.10.0 3.10.9