CVE-2026-76261: The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. in Splunk Splunk Enterprise
Description
CVE-2026-76261 affects certain versions of Splunk Enterprise and Splunk Secure Gateway. It allows users without admin or power roles to read Spacebridge asymmetric private keys via the Splunk Secure Gateway App Key Value Store REST API if the private-key migration from older deployments is incomplete. This occurs due to insecure default access control lists on key material collections. The vulnerability is rated medium severity with a CVSS score of 5.3.
CVSS v3.1
Score 5.3medium
Affected software
Splunk
Splunk Enterprise
Splunk
Splunk Secure Gateway
pkg:github/splunk/splunk-secure-gatewayRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.9, 3.9.23, and 3.8.70, a vulnerability exists where users lacking admin or power roles can read Spacebridge asymmetric private keys. This is possible when instances upgraded from older Splunk Secure Gateway deployments have incomplete private-key migration, leaving key material stored in a collection with insecure default access control lists accessible through the Splunk Secure Gateway App Key Value Store REST API. The exposure of these private keys compromises the confidentiality of Spacebridge private-key material.
Potential Impact
The vulnerability allows unauthorized users with limited privileges to read sensitive asymmetric private keys used by Spacebridge, potentially compromising the confidentiality of cryptographic material. There is no indication of integrity or availability impact. Exploitation requires that the private-key migration is incomplete, which is a condition present in upgraded instances from older deployments.
Mitigation Recommendations
A fix is available in Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions 3.10.9, 3.9.23, and 3.8.70. Users should upgrade to these or later versions to remediate the vulnerability. The vulnerability arises from incomplete private-key migration; completing the migration process and ensuring proper access control lists on key material collections will mitigate the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2026-08-19T12:02:03.619Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a862251acd9273b49a6fd9b
Added to database: 08/19/2026, 21:38:25 UTC
Last enriched: 09/11/2026, 07:18:42 UTC
Last updated: 10/04/2026, 10:04:22 UTC
Views: 40
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.