Improper access control in Splunk Enterprise - CVE-2026-76345

 

Improper access control in Splunk Enterprise - CVE-2026-76345

Published: August 20, 2026


Vulnerability identifier: #VU144477
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76345
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the search head cluster member bundle REST API when validating bundle paths and accepting bundle content. A remote privileged user can use the REST API to write files to writable locations and execute arbitrary code.


Affected software

Splunk Enterprise

How to mitigate CVE-2026-76345

Install security update from vendor's website.

Splunk Enterprise - addressed in versions 9.4.14, 10.0.9, 10.2.6, 10.4.2

External References

Related Security Bulletins