CVE-2026-76314 – Splunk Enterprise

CVSS 8.8 IMPORTANT Critical - Same Day Deployment

“Weak authorization boundaries can expose session material, elevate low-privileged users, and open multiple paths to code execution.”

Splunk Enterprise fixes three Critical and fourteen High-severity vulnerabilities affecting embedded reports, scheduled searches, distributed and federated search, Splunk Web Manager configuration, scripted lookups, authentication tokens, SPL2 modules, Edge Processor, and related REST APIs. The most severe issues allow unauthenticated users with embedded report access to recover session material and access data or administrative capabilities belonging to the report owner. CVE-2026-76310, CVE-2026-76311, and CVE-2026-76312 each have a CVSS score of 9.4, Critical severity.

Multiple High-severity issues can enable privilege escalation or remote code execution by lower-privileged users. CVE-2026-76314, CVE-2026-76315, and CVE-2026-76335 allow arbitrary code or operating-system command execution through Splunk Web Manager configuration, while CVE-2026-76313 and CVE-2026-76319 provide additional RCE paths through distributed or federated search workflows. CVE-2026-76253, CVE-2026-76259, CVE-2026-76350, and CVE-2026-76352 can expose credentials or run actions with elevated privileges. Most fixes are included in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14, with some version-specific exceptions.

Key Details

Affected Product
Splunk Splunk
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-94
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.