Splunk Enterprise versions 9.4.x are not affected.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.
Workaround
Turn off or remove the Splunk App for Splunk Observability Cloud. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-1001 |
|
Wed, 07 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens (https://help.splunk.com/en/splunk-observability-cloud/administer/authentication-and-security/authentication-tokens) in the Splunk documentation. Splunk Enterprise versions 9.4.x are not affected. | |
| Title | Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observability Cloud | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-10-07T20:46:34.443Z
Reserved: 2026-08-19T12:02:03.620Z
Link: CVE-2026-76274
No data.
Status : Received
Published: 2026-10-07T21:17:18.477
Modified: 2026-10-07T21:17:18.477
Link: CVE-2026-76274
No data.
OpenCVE Enrichment
No data.