PT-2026-78735 · Splunk · Splunk Enterprise
CVE-2026-76263
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions 10.2 through 10.2.5
Splunk Enterprise versions 10.4 through 10.4.1
Description
A broken object level authorization issue exists in the data management orchestrator interface. This occurs because the orchestrator fails to verify if the requesting user owns the target resources before deleting them. Consequently, a user without "admin" or "power" roles can delete Splunk Processing Language version 2 (SPL2) modules belonging to other users.
Recommendations
Update Splunk Enterprise versions 10.2.x to 10.2.6.
Update Splunk Enterprise versions 10.4.x to 10.4.2.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Enterprise