---
id: CVE-2026-76280
title: >-
  In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and
  Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an
  authenticated user who does not hold the "admin" or "sc_admin" Splunk roles
  could modify Sp…
summary: >-
  In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and
  Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an
  authenticated user who does not hold the "admin" or "sc_admin" Splunk roles
  could modify Sp…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-732
vendor: Splunk
product: Splunk Enterprise
affected:
  - enterprise >= 10.4 < 10.4.3
  - enterprise >= 10.2 < 10.2.7
  - enterprise >= 10.0 < 10.0.10
  - enterprise >= 9.4 < 9.4.15
  - secure_gateway >= 3.10 < 3.10.11
  - secure_gateway >= 3.9 < 3.9.25
  - secure_gateway >= 3.8 < 3.8.72
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:17:19.327'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76280'
references:
  - url: 'https://advisory.splunk.com/advisories/SVD-2026-1001'
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T21:54:15.097Z'
---

## Overview

In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the "admin" or "sc_admin" Splunk roles could modify Splunk Secure Gateway alert and mobile-device recipient data in App Key Value Store (KV Store) collections that later alert and subscription workflows use. The vulnerability is possible because the affected collections allow unrestricted write access instead of limiting writes to authorized Splunk Secure Gateway workflows. For more information see About the app key value store (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/administer-the-app-key-value-store/about-the-app-key-value-store), KV store endpoint descriptions (https://help.splunk.com/en/splunk-enterprise/leverage-rest-apis/rest-api-reference/10.4/kv-store-endpoints/kv-store-endpoint-descriptions), and About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
