Improper access control in Splunk Enterprise - CVE-2026-76312
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to access data and affect system integrity.
The vulnerability exists due to improper access control in embedded reports when enforcing the dispatch archive authorization boundary. A remote attacker can read the HTML source of a page that embeds a Splunk report to use exposed session material.
Exploitation requires access to the HTML source of a page that embeds a Splunk report.