Junglewise Threat Intelligence

CVE-2026-76355: Splunk Enterprise Edge Processor pipeline information disclosure

CVE-2026-76355 · Severity: high · CVSS 7.5 · Published 2026-08-19

Technologies: Splunk, Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise 10.4 versions below 10.4.2 contain an unauthenticated information disclosure vulnerability in the Edge Processor feature. An attacker without credentials can retrieve sensitive pipeline configuration data through a REST API endpoint, potentially exposing operational details about how data is processed. This affects deployments that have enabled Edge Processor, a feature for processing data at the network edge.

Technical details

The vulnerability exists in the Edge Processor service endpoint, which lacks proper authentication controls on its REST API. An unauthenticated attacker can directly access the endpoint to retrieve pipeline configuration information when the Edge Processor feature is enabled. The attack requires network access to the REST API but no authentication credentials or user interaction. Successful exploitation allows an attacker to enumerate and extract configuration details that could be used for reconnaissance or to identify further attack opportunities. The vulnerability is specific to Splunk Enterprise 10.4.0–10.4.1 and has been patched in version 10.4.2.

Affected products

  • Splunk Enterprise 10.4.0 to 10.4.1

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 10.4.2

References

Related threats