← All Advisories

Splunk Enterprise Edge Processor SPL2 Sidecar Exposes Prometheus Metrics to Unauthenticated Callers

Last refreshed2026-09-29

Status: UPDATED  |  Advisory ID: CVE-2026-76262

Key Details

CVECVE-2026-76262
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-08-26
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsSplunk splunk
Classified asCWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Splunksplunk
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could read Prometheus service metrics from the Edge Processor SPL2 Preview sidecar, including service details that expose relevant runtime and build metadata for the sidecar. The vulnerability does not affect Splunk Enterprise versions below 10.4. The information disclosure is possible because the Prometheus metrics endpoint in the Edge Processor SPL2 Preview sidecar lacks authentication, which lets any client that can reach the sidecar retrieve the metrics without credentials. For more information see About Splunk sidecars (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/splunk-sidecars/about-splunk-sidecars) in the Splunk documentation. (NVD)

What to Do

Monitor Splunk's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-76262
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-76262
Vendor advisoryhttps://advisory.splunk.com/advisories/SVD-2026-0801