PT-2026-107699 · Splunk · Splunk Enterprise

CVE-2026-76277

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

4.1

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.3 Splunk Enterprise versions prior to 10.2.7 Splunk Enterprise versions prior to 10.0.10 Splunk Enterprise versions prior to 9.4.15
Description Improper input validation in the REST API allows a user with the edit user capability to create a native username ending with a period. Because the system fails to reject trailing periods during validation, distinct usernames may share per-user configuration data. This can lead to user-management operations affecting the incorrect account or failing entirely.
Recommendations Update to version 10.4.3 or later. Update to version 10.2.7 or later. Update to version 10.0.10 or later. Update to version 9.4.15 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76277

Affected Products

Splunk Enterprise