What is CVE-2026-76351?
CVE-2026-76351 is a vulnerability in Splunk Enterprise and Splunk Secure Gateway. A user without 'admin' or 'power' roles can use crafted report notification data to cause Splunk Secure Gateway to send requests to an arbitrary destination. Affected users should update to the patched versions immediately.
Azərbaycanca: CVE-2026-76351, Splunk Enterprise və Splunk Secure Gateway-də aşkar edilmiş zəiflikdir. 'admin' və ya 'power' roluna malik olmayan istifadəçi xüsusi hazırlanmış hesabat bildiriş məlumatları vasitəsilə Splunk Secure Gateway-in istənməyən sorğu göndərməsinə səbəb ola bilər. Təsirə məruz qalan versiyaları müvafiq təhlükəsizlik yamaları ilə yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Splunk
FAQ2
What privileges does an attacker need to exploit CVE-2026-76351?
The attacker only needs to be a user without the 'admin' or 'power' roles to exploit this vulnerability.
What measure should be taken to mitigate the impact of CVE-2026-76351?
Affected users should update Splunk Enterprise and Splunk Secure Gateway to the corresponding patched versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.