---
id: CVE-2026-76278
title: >-
  In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that
  holds a role with the edit_spl2_module_permissions capability could use the
  affected Representational State Transfer (REST) API to access permission
  grants for …
summary: >-
  In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that
  holds a role with the edit_spl2_module_permissions capability could use the
  affected Representational State Transfer (REST) API to access permission
  grants for …
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: Splunk
product: Splunk Enterprise
affected:
  - enterprise >= 10.4 < 10.4.3
  - enterprise >= 10.2 < 10.2.7
  - enterprise >= 10.0 < 10.0.10
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:17:19.043'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76278'
references:
  - url: 'https://advisory.splunk.com/advisories/SVD-2026-1001'
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T21:54:15.097Z'
---

## Overview

In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State Transfer (REST) API to access permission grants for SPL2 modules that the user does not have permission to view. The vulnerability is possible because Splunk Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. For more information see Module permissions (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/modules-statements-and-views/module-permissions) and Manage SPL2 modules (https://help.splunk.com/en/splunk-enterprise/search/spl2-search-manual/multiple-searches-in-an-spl2-module/manage-spl2-modules) in the Splunk documentation.

Splunk Enterprise versions 9.4.x are not affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
