Vulnerability Description
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. The vulnerability does not affect Splunk Enterprise versions below 10.4. The vulnerability is possible because the REST API does not require authentication or the change_authentication capability for the token-key reload action. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Splunk | Splunk | >= 10.4.0, < 10.4.2 |
Related Weaknesses (CWE)
References
- https://advisory.splunk.com/advisories/SVD-2026-0801Vendor Advisory
FAQ
What is CVE-2026-76340?
CVE-2026-76340 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could cause Splunk Enterprise to reload token-signing keys through the Representational State Transfer (REST) API. The vulnerab...
How severe is CVE-2026-76340?
CVE-2026-76340 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-76340?
Check the references section above for vendor advisories and patch information. Affected products include: Splunk Splunk.