CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-76390

mediumCVSS 5.3covered by 1 sourcefirst seen 2026-08-19
In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and authentication model. The vulnerability is possible because the generated OpenAPI specification is packaged in a static file path that Splunk Web serves without authentication. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.

⚡ Watch CVE-2026-76390

Get an email if CVE-2026-76390 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-76390

CVE.org record

Embed the live status

CVE-2026-76390 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-76390 status](https://www.csirts.com/badge/CVE-2026-76390)](https://www.csirts.com/cve/CVE-2026-76390)