Improper access control in Splunk Enterprise - CVE-2026-76311
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to access data and affect system integrity.
The vulnerability exists due to improper access control in embedded report dispatch archives when processing archive download requests. A remote attacker can use an embedded report token to download a dispatch archive and use exposed session material.
Exploitation requires possession of an embedded report token.