SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76353

MEDIUM · CVSS 5.4 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to unauthorized file deletion by users lacking "admin" or "power" roles, due to inadequate restrictions on knowledge bundle delta processing. This could lead to system integrity issues and service disruptions. Organizations using affected versions should prioritize patching to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-76353
Severity
MEDIUM
CVSS
5.4
EPSS
0.28%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could submit a crafted knowledge bundle delta to delete arbitrary files accessible to Splunk Enterprise on a cluster manager. This could affect system integrity and disrupt service. The vulnerability is possible because knowledge bundle delta processing does not restrict removal paths to the staging directory and the endpoint does not enforce the expected authorization boundary. For more information see Knowledge bundle replication overview (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/knowledge-bundle-replication/knowledge-bundle-replication-overview) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)