CVE-2026-76267: Log Injection through the REST API in Splunk App for Splunk O11y Cloud
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the reado11ycontent capability could inject forged entries into the app log through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk App for Splunk O11y Cloud does not neutralize user-supplied SignalFlow content before writing it to the app log.
Splunk Enterprise versions 9.4.x are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.10 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.15
Event History
Frequently Asked Questions
Which users can exploit this issue?
An attacker needs an authenticated Splunk user account assigned a role with the read_o11y_content capability. No user interaction is required.
Which deployments are affected?
Splunk Enterprise releases below 10.4.3, 10.2.7, and 10.0.10 are affected when the Splunk App for Splunk O11y Cloud is in use. Splunk Enterprise 9.4.x is not affected.
What is the impact of successful exploitation?
A permitted user can submit SignalFlow content through the REST API that results in forged entries in the app log. The provided severity vector indicates integrity impact only, with no stated confidentiality or availability impact.
What can be done before upgrading?
Limit assignment of the read_o11y_content capability to trusted users, since that capability is required for exploitation. Review app logs for suspicious or forged-looking entries, particularly where log content could have originated from user-supplied SignalFlow.