PT-2026-78772 · Splunk · Splunk Enterprise

CVE-2026-76345

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

6.0

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions 10.4 through 10.4.1
Description A user with a high-privilege role capable of managing search head clustering can exploit the search head cluster member bundle REST API to write files to locations accessible by the account running the software. This occurs because the API fails to enforce authorization boundaries and does not validate bundle paths before accepting content, potentially leading to remote code execution. Successful exploitation may compromise the integrity and availability of the deployment and grant access to all relevant data.
Recommendations Update Splunk Enterprise to version 10.4.2.

Fix

RCE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76345

Affected Products

Splunk Enterprise