SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76263

MEDIUM · CVSS 5.4 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

In Splunk Enterprise versions prior to 10.4.2 and 10.2.6, users lacking "admin" or "power" roles can exploit a broken object level authorization flaw to delete SPL2 modules belonging to other users via the data management orchestrator interface. This vulnerability could lead to unauthorized data loss and disruption of services for affected users. Organizations using these versions should prioritize patching to mitigate potential risks associated with unauthorized access and data management.

CVE
CVE-2026-76263
Severity
MEDIUM
CVSS
5.4
EPSS
0.22%

Original NVD Description

In Splunk Enterprise versions below 10.4.2 and 10.2.6, a user who does not hold the "admin" or "power" Splunk roles could delete Splunk Processing Language version 2 (SPL2) modules belonging to other users through the data management orchestrator interface. The vulnerability does not affect Splunk Enterprise versions below 10.2. The broken object level authorization is possible because the data management orchestrator does not verify that the requesting user owns the target resources before it deletes the modules. For more information see Manage SPL2-based apps (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/meet-splunk-apps/manage-spl2-based-apps) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)