SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76335

HIGH · CVSS 8.8 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to a privilege escalation flaw that allows authenticated users lacking the edit_manager_xml capability to inject malicious XML configurations. This can lead to the execution of arbitrary operating system commands under the context of the Splunk Enterprise user account, potentially compromising the system. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-76335
Severity
HIGH
CVSS
8.8
EPSS
0.33%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an authenticated user who does not hold a role with the edit_manager_xml capability could write a malicious Splunk Web Manager Extensible Markup Language (XML) configuration. When the same user opens the affected Splunk Web Manager page, Splunk Enterprise runs attacker-controlled operating-system commands as the user account running Splunk Enterprise. The vulnerability is possible because Splunk Web does not require the edit_manager_xml capability before accepting Splunk Web Manager XML configuration changes.

Related CVEs

Other vulnerabilities affecting the same vendor(s)