PT-2026-78817 · Splunk+1 · Splunk Web+1

CVE-2026-76390

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Talos Intelligence for Enterprise Security Cloud versions prior to 1.0.3
Description An unauthenticated user can access the add-on OpenAPI specification via Splunk Web static file paths. This exposure occurs because the generated OpenAPI specification is stored in a static file path that Splunk Web serves without requiring authentication. This could allow an attacker to perform reconnaissance on the add-on Representational State Transfer (REST) API endpoints and the authentication model.
Recommendations Update to version 1.0.3 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76390

Affected Products

Splunk Web
Cisco Talos Intelligence For Enterprise Security Cloud