PT-2026-78731 · Splunk · Splunk Enterprise

·

CVE-2026-76259

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk Enterprise for Windows versions prior to 10.4.2 Splunk Enterprise for Windows versions prior to 10.2.6 Splunk Enterprise for Windows versions prior to 10.0.9 Splunk Enterprise for Windows versions prior to 9.4.13 Splunk Enterprise for Windows versions prior to 9.3.14
Description A local user with access to the Windows host can bind to the management port before the service starts. This occurs because the Windows management-port listener fails to apply exclusive address binding protections. An attacker can intercept authentication tokens from child processes to compromise system integrity and access data available to the account running the software.
Recommendations Update to version 10.4.2 or later. Update to version 10.2.6 or later. Update to version 10.0.9 or later. Update to version 9.4.13 or later. Update to version 9.3.14 or later.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76259

Affected Products

Splunk Enterprise