SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76344

HIGH · CVSS 7.7 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to an issue where non-admin users can exploit a REST API endpoint to write dispatch metadata to arbitrary locations on the host, compromising system integrity. This flaw arises from the lack of validation for search identifiers, allowing unauthorized access to critical system functions. Organizations using affected versions, particularly those with user roles that do not include admin or power privileges, should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-76344
Severity
HIGH
CVSS
7.7
EPSS
0.30%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Representational State Transfer (REST) API endpoint and affect system integrity on the host. The vulnerability is possible because Splunk Enterprise does not validate the search identifier before using it to create a dispatch directory. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)