CVE-2026-76352 – Splunk Enterprise
“Weak authorization boundaries can expose session material, elevate low-privileged users, and open multiple paths to code execution.”
Splunk Enterprise fixes three Critical and fourteen High-severity vulnerabilities affecting embedded reports, scheduled searches, distributed and federated search, Splunk Web Manager configuration, scripted lookups, authentication tokens, SPL2 modules, Edge Processor, and related REST APIs. The most severe issues allow unauthenticated users with embedded report access to recover session material and access data or administrative capabilities belonging to the report owner. CVE-2026-76310, CVE-2026-76311, and CVE-2026-76312 each have a CVSS score of 9.4, Critical severity.
Multiple High-severity issues can enable privilege escalation or remote code execution by lower-privileged users. CVE-2026-76314, CVE-2026-76315, and CVE-2026-76335 allow arbitrary code or operating-system command execution through Splunk Web Manager configuration, while CVE-2026-76313 and CVE-2026-76319 provide additional RCE paths through distributed or federated search workflows. CVE-2026-76253, CVE-2026-76259, CVE-2026-76350, and CVE-2026-76352 can expose credentials or run actions with elevated privileges. Most fixes are included in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, and 9.4.14, with some version-specific exceptions.
Key Details
- Affected Product
- Splunk Splunk
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-285