Sceawere
Vulnerability Detail
CVE-2026-76262UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Splunk Enterprise Information Disclosure Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 2h ago
- Vendor
- Splunk
- Product
- Splunk Enterprise
- Attack Type
- The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is possible because the Prometheus metrics endpoint in the Edge Processor SPL2 Preview sidecar lacks authentication, which lets any client that can reach the sidecar retrieve the metrics without credentials. For more information see About Splunk sidecars (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/splunk-sidecars/about-splunk-sidecars) in the Splunk documentation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-19T22:17:14.323Z",
"pubdate": "2026-08-19T22:17:14.323Z",
"executiveSummary": "An unauthenticated information disclosure vulnerability has been identified in Splunk Enterprise versions 10.4 through 10.4.1 within the Edge Processor SPL2 Preview sidecar.\nThe vulnerability allows remote, unauthenticated attackers to read sensitive Prometheus service metrics, exposing critical runtime and build metadata associated with the sidecar.\nThe primary impact is the unauthorized exposure of internal system metrics and operational metadata, which can be leveraged by malicious actors to map the internal architecture and identify potential secondary attack vectors.\nThe risk implication centers on reconnaissance capabilities granted to network-adjacent or unauthenticated threat actors who can reach the affected sidecar endpoint.\nExploitation requires no privileges or authentication, provided the attacker has network connectivity to the Prometheus metrics endpoint exposed by the Edge Processor SPL2 Preview sidecar.\nSystems affected are strictly limited to Splunk Enterprise 10.4 versions below 10.4.2 utilizing the Edge Processor SPL2 Preview sidecar.",
"technicalDetails": "The root cause of the vulnerability is the complete lack of authentication mechanisms on the Prometheus metrics endpoint hosted within the Edge Processor SPL2 Preview sidecar component of Splunk Enterprise.\nThe vulnerable component is the metrics ingestion and exposition interface of the Edge Processor SPL2 Preview sidecar.\nAffected versions are strictly confined to Splunk Enterprise 10.4 versions below 10.4.2.\nAuthentication and privilege requirements are entirely absent; any client capable of reaching the metrics endpoint can successfully retrieve data without credentials.\nNetwork exposure is defined by the reachability of the Prometheus metrics endpoint exposed by the sidecar.\nThe step-by-step attack flow proceeds as follows: First, an unauthenticated client identifies or targets the network location hosting the Edge Processor SPL2 Preview sidecar's Prometheus metrics endpoint. Second, the client issues a standard HTTP request to retrieve the metrics without supplying any authentication headers, tokens, or credentials. Third, the sidecar processes the request and returns the unauthenticated payload containing Prometheus service metrics. Finally, the attacker parses the returned payload to extract sensitive runtime parameters, build metadata, and service details.\nPost-exploitation impact involves leveraging the harvested build metadata and runtime details to facilitate further targeted attacks against the Splunk Enterprise deployment or underlying infrastructure."
}