Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Younes Zendour

#44529of 57,627
6.5Total CVSS
Vulnerabilities · 1
PT-2026-107687
6.5
2026-10-07
Splunk · Splunk Secure Gateway App · CVE-2026-76265
**Name of the Vulnerable Software and Affected Versions** Splunk Enterprise versions prior to 10.4.3 Splunk Enterprise versions prior to 10.2.7 Splunk Enterprise versions prior to 10.0.10 Splunk Enterprise versions prior to 9.4.15 Splunk Secure Gateway versions prior to 3.10.11 Splunk Secure Gateway versions prior to 3.9.25 Splunk Secure Gateway versions prior to 3.8.72 **Description** Users without admin or power roles can access privileged functionality within Splunk Secure Gateway. This is caused by multiple Representational State Transfer (REST) API endpoints that fail to enforce authorization requirements before processing requests. An attacker can exploit this to force Splunk Secure Gateway to sign attacker-controlled payloads. **Recommendations** Update Splunk Enterprise to version 10.4.3 or later. Update Splunk Enterprise to version 10.2.7 or later. Update Splunk Enterprise to version 10.0.10 or later. Update Splunk Enterprise to version 9.4.15 or later. Update Splunk Secure Gateway to version 3.10.11 or later. Update Splunk Secure Gateway to version 3.9.25 or later. Update Splunk Secure Gateway to version 3.8.72 or later.