In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and authentication model. The vulnerability is possible because the generated OpenAPI specification is packaged in a static file path that Splunk Web serves without authentication. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.

Project Subscriptions

Vendors Products
Talos Intelligence For Enterprise Security Cloud Subscribe
Cisco Talos Intelligence For Enterprise Security Cloud Subscribe
Advisories

No advisories yet.

Fixes

Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Workaround

Turn off or remove the Cisco Talos Intelligence for Enterprise Security Cloud app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.

History

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco talos Intelligence For Enterprise Security Cloud
CPEs cpe:2.3:a:cisco:talos_intelligence_for_enterprise_security_cloud:*:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco talos Intelligence For Enterprise Security Cloud

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk cisco Talos Intelligence For Enterprise Security Cloud
Vendors & Products Splunk
Splunk cisco Talos Intelligence For Enterprise Security Cloud

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational State Transfer (REST) API endpoints and authentication model. The vulnerability is possible because the generated OpenAPI specification is packaged in a static file path that Splunk Web serves without authentication. For more information see Deploy Cisco Talos Intelligence for Splunk Enterprise Security (https://help.splunk.com/en/splunk-enterprise-security-8/user-guide/8.0/introduction/deploy-cisco-talos-intelligence-for-splunk-enterprise-security-cloud-only) in the Splunk documentation.
Title Information Disclosure through Splunk Web in Cisco Talos Intelligence for Enterprise Security Cloud
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:30.600Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76390

cve-icon Vulnrichment

Updated: 2026-08-20T16:20:56.845Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:25.357

Modified: 2026-08-21T19:18:17.943

Link: CVE-2026-76390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses