Improper privilege management in Splunk Enterprise - CVE-2026-76259

 

Improper privilege management in Splunk Enterprise - CVE-2026-76259

Published: August 20, 2026


Vulnerability identifier: #VU144437
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76259
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper privilege management in the Windows management-port listener when the Splunk Enterprise service starts. A local user can bind to the management port before Splunk Enterprise starts to intercept authentication tokens from child processes.

Exploitation requires access to the Windows host.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76259

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins