AUGUST 26, 2026
Live Feed
Back to database
Case File

CVE-2026-76405

MEDIUM · CVSS 4.3 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-08-25

CyberRota Analysis

AI-Generated

The Splunk On-Call (VictorOps) app versions prior to 1.0.43 are vulnerable as they allow non-admin users to access a partially masked API key stored in the App Key Value Store. This exposure could lead to unauthorized access to sensitive functionalities or data associated with the API. Organizations using affected versions of the app should prioritize updating to mitigate potential security risks.

CVE
CVE-2026-76405
Severity
MEDIUM
CVSS
4.3
EPSS
0.14%

Original NVD Description

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/administer-the-app-key-value-store/about-the-app-key-value-store) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)