Junglewise Threat Intelligence

CVE-2026-76347: Splunk Enterprise SSRF in report notifications

CVE-2026-76347 · Severity: medium · CVSS 5.4 · Published 2026-08-19

Technologies: Splunk Enterprise, Splunk Secure Gateway. Vendors: Splunk.

Executive brief

Splunk Enterprise and Secure Gateway contain a Server-Side Request Forgery vulnerability in their report notification system that allows non-admin users to send authenticated requests to internal Splunk services. An attacker could exploit this to modify Search Head Cluster state or trigger denial-of-service conditions, compromising the availability and integrity of Splunk deployments.

Technical details

CVE-2026-76347 is a Server-Side Request Forgery (SSRF) vulnerability in Splunk Enterprise and Secure Gateway's report notification functionality. The root cause is insufficient validation of report notification path values before sending internal authenticated requests. An unauthenticated or low-privileged user (without "admin" or "power" roles) can craft malicious notification paths to send system-authenticated requests to internal Splunk services, potentially modifying Search Head Cluster state or causing denial of service. The vulnerability affects Splunk Enterprise versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions before 3.10.9, 3.9.23, and 3.8.70. Patches are available in the fixed versions.

Affected products

  • Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, 9.4.14
  • Splunk Secure Gateway before 3.10.9, 3.9.23, 3.8.70

Timeline

  • 2026-08-19: disclosed

References

Related threats