Improper Neutralization of Null Byte or NUL Character in Splunk Enterprise - CVE-2026-76354
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to delete or overwrite files.
The vulnerability exists due to improper neutralization of NUL bytes in Search Head Clustering bundle replication when constructing member bundle paths. A remote user can send crafted REST API requests to delete or temporarily overwrite files writable by Splunk Enterprise processes.
The target described is a non-captain search head cluster member.