Improper Authorization in Splunk Enterprise - CVE-2026-76352

 

Improper Authorization in Splunk Enterprise - CVE-2026-76352

Published: August 20, 2026


Vulnerability identifier: #VU144426
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76352
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper authorization in generic transforms configuration endpoints when creating or modifying scripted lookup definitions through the REST API. A remote user can create or modify a scripted lookup to execute arbitrary code.

The issue involves installed lookup scripts running with the permissions of the user account running Splunk Enterprise.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76352

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins