Junglewise Threat Intelligence

CVE-2026-76340: Splunk Enterprise missing authorization for token-signing key reload in REST API

CVE-2026-76340 · Severity: medium · CVSS 5.3 · Published 2026-08-19

Technologies: Splunk, Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise is a widely-used data analytics and logging platform. An unauthenticated attacker could trigger a reload of token-signing keys via the REST API, potentially disrupting authentication systems and affecting the availability of security functions that depend on these keys. This vulnerability only affects Splunk Enterprise 10.4 versions below 10.4.2.

Technical details

This is a missing authorization vulnerability (CWE-862) in the Splunk Enterprise REST API. The token-key reload action does not validate authentication status or the change_authentication capability, allowing unauthenticated users to trigger the operation. An attacker can make a network request to the affected REST endpoint without credentials to reload the token-signing keys. This could cause denial of service or disrupt authentication-dependent features. The vulnerability is limited to Splunk Enterprise 10.4.0 and 10.4.1; versions below 10.4 are unaffected. Patch available in version 10.4.2 and later.

Affected products

  • Splunk Enterprise 10.4.0 to 10.4.1

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 10.4.2

References

Related threats