Improper Authorization in Splunk Enterprise - CVE-2026-76352
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper authorization in generic transforms configuration endpoints when creating or modifying scripted lookup definitions through the REST API. A remote user can create or modify a scripted lookup to execute arbitrary code.
The issue involves installed lookup scripts running with the permissions of the user account running Splunk Enterprise.