Improper Authentication in Splunk Enterprise - CVE-2026-76338
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to forge an administrative session token.
The vulnerability exists due to improper authentication in distributed search authentication token endpoint when processing distributed search token requests. A remote attacker can send a crafted token request to forge an administrative session token.
Exploitation requires access to a trusted distributed search private key.