Missing Authorization in Splunk Enterprise - CVE-2026-76348
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to missing authorization in Search Head Cluster member control endpoints when applying read-only authorization to state-changing actions. A remote privileged user can send a read request to member control endpoints to change cluster state.