CVE-2026-76340: The software does not perform an authorization check when an actor attempts to access a resource or perform an action. in Splunk Splunk Enterprise
Description
CVE-2026-76340 is a medium severity vulnerability in Splunk Enterprise versions 10.4 up to but not including 10.4.2. It allows an unauthenticated user to reload token-signing keys via the REST API because the API does not require authentication or the necessary capability for this action. Versions prior to 10.4 are not affected.
CVSS v3.1
Score 5.3medium
Affected software
Splunk
Splunk Enterprise
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Splunk Enterprise versions >=10.4 and <10.4.2, the REST API permits unauthenticated users to trigger a reload of token-signing keys without performing an authorization check. This occurs because the REST API endpoint responsible for the token-key reload action does not require authentication or the 'change_authentication' capability. This flaw could allow an attacker to interfere with token management processes, potentially impacting integrity but not confidentiality or availability.
Potential Impact
The vulnerability allows an unauthenticated attacker to cause Splunk Enterprise to reload token-signing keys. According to the CVSS vector, this does not compromise confidentiality or availability but can impact integrity. There is no indication of active exploitation in the wild. The impact is limited to the ability to reload keys without authorization, which could disrupt token-based authentication mechanisms.
Mitigation Recommendations
A fixed version, 10.4.2, is available that addresses this vulnerability. Users should upgrade to Splunk Enterprise version 10.4.2 or later to remediate the issue. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2026-08-19T12:02:03.627Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a862257acd9273b49a6fea1
Added to database: 08/19/2026, 21:38:31 UTC
Last enriched: 09/11/2026, 07:03:43 UTC
Last updated: 10/04/2026, 10:04:19 UTC
Views: 37
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.