Improper access control in Splunk Enterprise - CVE-2026-76313
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the knowledge bundle upload REST API and distributed search bundle selection when handling caller-supplied knowledge bundles. A remote user can upload a malicious knowledge bundle and cause distributed search to use it to execute arbitrary code.