
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76355 is an information disclosure vulnerability in Splunk Enterprise affecting the Edge Processor REST API endpoint, classified as Missing Authentication for Critical Function (CWE-306). An unauthenticated remote attacker can retrieve Edge Processor pipeline configuration data when the Edge Processor feature is enabled. Only Splunk Enterprise versions 10.4.0 through 10.4.1 are affected; versions prior to 10.4 are not impacted. The vulnerability was published on August 19, 2026, with a patch available in version 10.4.2. It carries a CVSS v3.1 base score of 7.5 (High) (Splunk Advisory, GitHub Advisory).
The root cause is CWE-306 (Missing Authentication for Critical Function): the Edge Processor service REST API endpoint in Splunk Enterprise 10.4.x was deployed without authentication controls, allowing any network-accessible client to query it without credentials. An attacker simply sends an unauthenticated HTTP GET request to the exposed REST API endpoint to retrieve Edge Processor pipeline configuration data. No privileges, user interaction, or special conditions are required beyond the Edge Processor feature being enabled in the deployment. No public proof-of-concept code has been identified at this time (Splunk Advisory, GitHub Advisory).
Successful exploitation results in unauthorized disclosure of Edge Processor pipeline configuration information, which may include data routing rules, processing logic, and potentially sensitive infrastructure details. The confidentiality impact is rated High, while integrity and availability are unaffected. Exposed pipeline configurations could assist an attacker in mapping the data processing architecture, facilitating further targeted attacks or lateral movement within the environment (Splunk Advisory, GitHub Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The EPSS score is 0.0, indicating a currently low probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only network access to the Splunk Enterprise instance with Edge Processor enabled, and no authentication, making it trivially exploitable if exposed to untrusted networks (GitHub Advisory, Splunk Advisory).
splunkd_access.log) showing REST API requests to Edge Processor endpoints with no associated authentication token or session, particularly from external or unknown IP addresses.Upgrade Splunk Enterprise to version 10.4.2 or later, which addresses the missing authentication control on the Edge Processor REST API endpoint. As an interim workaround, disable the Edge Processor feature if it is not required for your deployment. Additionally, implement network-level access controls (e.g., firewall rules) to restrict access to the Splunk REST API port (default 8089) to authorized hosts only (Splunk Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."