What is CVE-2026-76355?
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user can retrieve Edge Processor pipeline configuration information via a REST API endpoint when Edge Processor is enabled. Affected users should upgrade to version 10.4.2 or later to mitigate this vulnerability.
Azərbaycanca: Splunk Enterprise 10.4 versiyalarında (10.4.2-dən aşağı) autentifikasiya olunmamış istifadəçi Edge Processor aktiv olduqda REST API vasitəsilə pipeline konfiqurasiyalarındakı məlumatları əldə edə bilər. Splunk Enterprise istifadəçiləri bu boşluqdan qorunmaq üçün dərhal 10.4.2 və ya daha yuxarı versiyaya yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-306; shared vendor: Splunk
FAQ2
Which versions of Splunk Enterprise are affected by CVE-2026-76355?
All Splunk Enterprise 10.4 versions below 10.4.2 are affected by this vulnerability.
What should Splunk users do to protect against CVE-2026-76355?
Users should immediately upgrade Splunk Enterprise to version 10.4.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.