What is CVE-2026-76340?
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user can trigger a reload of token-signing keys via the REST API. This vulnerability only affects Splunk Enterprise 10.4 versions. Upgrading to version 10.4.2 or later is recommended to mitigate the issue.
Azərbaycanca: Splunk Enterprise 10.4-ün 10.4.2-dən aşağı versiyalarında autentifikasiya olunmamış istifadəçi REST API vasitəsilə token imzalama açarlarının yenidən yüklənməsinə səbəb ola bilər. Bu zəiflik yalnız Splunk Enterprise 10.4 versiyalarına təsir edir. Təsirə məruz qalmamaq üçün Splunk Enterprise-i 10.4.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which Splunk Enterprise versions are affected by CVE-2026-76340?
This vulnerability only affects Splunk Enterprise 10.4 versions below 10.4.2.
How can I mitigate CVE-2026-76340?
Upgrading Splunk Enterprise to version 10.4.2 or later is recommended to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.