PT-2026-78781 · Splunk · Splunk Enterprise

CVE-2026-76354

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.4.2 Splunk Enterprise versions prior to 10.2.6 Splunk Enterprise versions prior to 10.0.9 Splunk Enterprise versions prior to 9.4.14
Description A user without admin or power roles can compromise system integrity and availability by sending a crafted Representational State Transfer (REST) API request. This allows the deletion or temporary overwriting of files writable by the account running Splunk Enterprise processes on a non-captain search head cluster member. The issue occurs because Search Head Clustering bundle replication fails to validate the name of a replicated bundle file or neutralize NUL bytes (null characters used to terminate strings in some programming languages) before constructing the member bundle path.
Recommendations Update to version 10.4.2 or later. Update to version 10.2.6 or later. Update to version 10.0.9 or later. Update to version 9.4.14 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76354

Affected Products

Splunk Enterprise