Improper access control in Splunk Enterprise - CVE-2026-76345
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the search head cluster member bundle REST API when validating bundle paths and accepting bundle content. A remote privileged user can use the REST API to write files to writable locations and execute arbitrary code.