Security Vulnerabilities in Splunk Enterprise - September/October 2026
Advisory ID: SVD-2026-1001
Published: 2026-10-07
Highest CVSSv3.1 Score: 9.8, Critical
Last Updated: 2026-10-07
Description
Splunk addressed multiple vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. See CVE Details for vulnerability-specific affected versions, additional remediation, acknowledgments, and workarounds.
Solutions
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.
Additional steps are required to remedy the following CVEs:
CVE-2026-76264
CVE-2026-76265
CVE-2026-76272
CVE-2026-76280
Product Status
| Product | Base Version | Affected Version | Fix Version |
|---|---|---|---|
| Splunk Enterprise | 10.4 | 10.4.0 to 10.4.2 | 10.4.3 |
| Splunk Enterprise | 10.2 | 10.2.0 to 10.2.6 | 10.2.7 |
| Splunk Enterprise | 10.0 | 10.0.0 to 10.0.9 | 10.0.10 |
| Splunk Enterprise | 9.4 | 9.4.0 to 9.4.14 | 9.4.15 |
Vulnerabilities
| CVE | Summary | CWE | Severity | Score |
|---|---|---|---|---|
| CVE-2026-76264 | Improper Authorization through the REST API in Splunk Enterprise | CWE-863 | Medium | 4.3 |
| CVE-2026-76265 | Improper Access Control through REST API Endpoints in Splunk Secure Gateway | CWE-284 | Medium | 6.5 |
| CVE-2026-76266 | Local Privilege Escalation through Linux Package Upgrades in Splunk Enterprise | CWE-269 | High | 7.7 |
| CVE-2026-76267 | Log Injection through the REST API in Splunk App for Splunk O11y Cloud | CWE-117 | Medium | 4.3 |
| CVE-2026-76268 | Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise | CWE-306 | Critical | 9.8 |
| CVE-2026-76269 | Improper Access Control in Search Job Retrieval through the REST API in Splunk Enterprise | CWE-639 | Medium | 6.5 |
| CVE-2026-76270 | Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splunk Enterprise | CWE-89 | Medium | 6.5 |
| CVE-2026-76271 | Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Splunk Enterprise | CWE-407 | Medium | 6.5 |
| CVE-2026-76272 | Missing Access Control through the REST API in Splunk Secure Gateway | CWE-862 | Medium | 4.3 |
| CVE-2026-76273 | Improper Input Validation through the collect Command in Splunk Enterprise | CWE-20 | Medium | 4.3 |
| CVE-2026-76274 | Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observability Cloud | CWE-918 | Medium | 6.5 |
| CVE-2026-76275 | Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise | CWE-285 | Medium | 4.3 |
| CVE-2026-76276 | Information Disclosure in the Discover Splunk Observability Cloud app through Splunk Web for Splunk Enterprise | CWE-1188 | Medium | 4.3 |
| CVE-2026-76277 | Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterprise | CWE-20 | Medium | 4.1 |
| CVE-2026-76278 | Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise | CWE-639 | Medium | 4.3 |
| CVE-2026-76279 | Improper Input Validation of Index Names through the collect Command in Splunk Enterprise | CWE-20 | Medium | 4.3 |
| CVE-2026-76280 | Incorrect Permission Assignment for App Key Value Store Collections in Splunk Secure Gateway | CWE-732 | Medium | 6.3 |
CVE Details
CVE-2026-76264: Improper Authorization through the REST API in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.10, and 9.4.15, a user who does not hold the “admin” or “power” Splunk roles could create or edit scripted lookup definitions through raw configuration endpoints. The vulnerability is possible because raw transforms configuration write paths do not apply external lookup capability checks before saving scripted lookup settings.
Additional Solution
After upgrading, set scripted_lookup_raw_write_enforcement = block in the limits.conf configuration file under [lookup], and then restart Splunk Enterprise. For more information see Configuration file reference in the Splunk documentation.
Bug IDs: VULN-45758, VULN-25081
CWE: CWE-863
CVSSv3.1 Score: 4.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Acknowledgments: M Mahdan Argya Syarif (0xbeludan), Saidina Hikam (xzyhellsing), Alex Hordijk (hordalex)
CVE-2026-76265: Improper Access Control through REST API Endpoints in Splunk Secure Gateway
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, a user who does not hold the “admin” or “power” Splunk roles could access privileged Splunk Secure Gateway functionality. With this access, the user could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because multiple Splunk Secure Gateway Representational State Transfer (REST) API endpoints do not enforce authorization requirements before processing requests.
Additional Solution
Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher.
Bug ID: VULN-66944
CWE: CWE-284
CVSSv3.1 Score: 6.5, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Mitigations and Workarounds
Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher. If you are not able to upgrade Splunk Enterprise or Splunk Secure Gateway, turn off or remove the Splunk Secure Gateway app. See Manage app and add-on objects in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.
Acknowledgments: Younes Zendour (m3l4n0ff)
CVE-2026-76266: Local Privilege Escalation through Linux Package Upgrades in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15 on Linux, a local user who can run commands as the user account running Splunk Enterprise could cause an affected Linux package upgrade to run attacker-controlled operating-system commands with root privileges. The vulnerability is possible because the Linux package maintainer script trusts existing Splunk Enterprise installation content when it performs upgrade operations with root privileges. The vulnerability requires an affected Linux package upgrade to occur after the local user modifies the installation. The local user should not be able to elevate privileges at will.
Bug ID: VULN-81606
CWE: CWE-269
CVSSv3.1 Score: 7.7, High
CVSSv3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Mitigations and Workarounds
Use a tar file instead of a Linux package to upgrade Splunk Enterprise. For more information see Upgrade on UNIX in the Splunk documentation.
Acknowledgments: Jean-Michel Remi Boudreau
CVE-2026-76267: Log Injection through the REST API in Splunk App for Splunk O11y Cloud
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could inject forged entries into the app log through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk App for Splunk O11y Cloud does not neutralize user-supplied SignalFlow content before writing it to the app log.
Splunk Enterprise versions 9.4.x are not affected.
Bug ID: VULN-83845
CWE: CWE-117
CVSSv3.1 Score: 4.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Mitigations and Workarounds
Turn off or remove the Splunk App for Splunk O11y Cloud. For more information see Manage app and add-on objects in the Splunk documentation.
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76268: Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings in the Splunk documentation.
Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Bug ID: VULN-79185
CWE: CWE-306
CVSSv3.1 Score: 9.8, Critical
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigations and Workarounds
Turn off the PostgreSQL sidecar by setting disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf if you do not use Edge Processor, OpAmp, or SPL2 data pipelines. Restart Splunk Enterprise to apply the change. For more information see Sidecar configuration settings and server.conf in the Splunk documentation.
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76269: Improper Access Control in Search Job Retrieval through the REST API in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the “admin” or “power” Splunk roles could use a user-controlled job identifier to access substantially all search job information from jobs that belong to other users, including search query text, job metadata, results, and preview results, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully validate job ownership before returning search job information.
Bug ID: VULN-77888
CWE: CWE-639
CVSSv3.1 Score: 6.5, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76270: Structured Query Language (SQL) Injection in the SPL2 Module Catalog in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, a user that holds a role with the list_spl2_modules capability could use SQL injection in SPL2 module filtering to access all relevant data available through the affected Representational State Transfer (REST) API, including private SPL2 module definitions belonging to other users. The vulnerability is possible because Splunk Enterprise and Splunk Cloud Platform do not parameterize user-supplied values before using them in database queries for SPL2 module filtering. For more information see Manage SPL2 modules and Module permissions in the Splunk documentation.
Splunk Enterprise versions 10.2.x, 10.0.x, and 9.4.x are not affected.
Bug ID: VULN-81516
CWE: CWE-89
CVSSv3.1 Score: 6.5, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Acknowledgments: Jean-Michel Remi Boudreau
CVE-2026-76271: Denial of Service (DoS) in the Discover Splunk Observability Cloud app for Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the “admin” or “power” Splunk roles could cause a denial of service against a Representational State Transfer (REST) API endpoint in the Discover Splunk Observability Cloud app. The vulnerability is possible because the app uses an inefficient regular expression to validate input submitted through the endpoint. For more information see About configuring role-based user access, Splunk Observability Cloud previews, and restmap.conf in the Splunk documentation.
Splunk Enterprise versions 9.4.x are not affected.
Bug ID: VULN-83842
CWE: CWE-407
CVSSv3.1 Score: 6.5, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Mitigations and Workarounds
Turn off or remove the Discover Splunk Observability Cloud app. For more information see Manage app and add-on objects in the Splunk documentation.
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76272: Missing Access Control through the REST API in Splunk Secure Gateway
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the “admin” or “power” Splunk roles could cause Splunk Secure Gateway to sign attacker-controlled payloads. The vulnerability is possible because Splunk Secure Gateway does not verify that the user is authorized to request a signature. Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72 are also affected. For more information see Define roles on the Splunk platform with capabilities in the Splunk documentation.
Additional Solution
Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher.
Bug ID: VULN-71728
CWE: CWE-862
CVSSv3.1 Score: 4.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Mitigations and Workarounds
Turn off or remove the Splunk Secure Gateway app. See Manage app and add-on objects in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76273: Improper Input Validation through the collect Command in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to add attacker-controlled content to system-level messages on the Splunk platform instance. The vulnerability is possible because the collect command does not validate the index name before processing the value. For more information see collect, Define roles on the Splunk platform with capabilities, and System endpoint descriptions in the Splunk documentation.
Bug ID: VULN-79186
CWE: CWE-20
CVSSv3.1 Score: 4.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Acknowledgments: Anton (therceman)
CVE-2026-76274: Server-Side Request Forgery (SSRF) through the REST API in Splunk App for Splunk Observability Cloud
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the read_o11y_content capability could redirect an outbound request from Splunk App for Splunk Observability Cloud through the Representational State Transfer (REST) API to an attacker-controlled host and disclose the configured Observability Cloud Application Programming Interface (API) token. The vulnerability is possible because Splunk App for Splunk Observability Cloud does not fully validate the destination of an outbound request. For more information see Authentication tokens in the Splunk documentation.
Splunk Enterprise versions 9.4.x are not affected.
Bug ID: VULN-86789
CWE: CWE-918
CVSSv3.1 Score: 6.5, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Mitigations and Workarounds
Turn off or remove the Splunk App for Splunk Observability Cloud. For more information see Manage app and add-on objects in the Splunk documentation.
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76275: Improper Authorization in Search Job Listings through the REST API in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user who does not hold the “admin” or “power” Splunk roles could access search query text and job metadata for jobs that belong to other users, including job identifiers, dispatch parameters, result counts, and execution metadata, through an Application Programming Interface (API) implemented as a Representational State Transfer (REST) API. The vulnerability is possible because the REST API does not fully enforce per-user authorization before it includes job information in search job listings.
Bug ID: VULN-77891
CWE: CWE-285
CVSSv3.1 Score: 4.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76276: Information Disclosure in the Discover Splunk Observability Cloud app through Splunk Web for Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the “admin” or “power” Splunk roles could retrieve original source code for the Discover Splunk Observability Cloud app through Splunk Web. The vulnerability is possible because production JavaScript bundles for the app contain embedded source maps that include original source code. For more information see About configuring role-based user access, Splunk Observability Cloud previews, and Navigating Splunk Web in the Splunk documentation.
Splunk Enterprise versions 9.4.x are not affected.
Bug ID: VULN-83843
CWE: CWE-1188
CVSSv3.1 Score: 4.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Mitigations and Workarounds
Turn off or remove the Discover Splunk Observability Cloud app. For more information see Manage app and add-on objects in the Splunk documentation.
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76277: Improper Input Validation of Native Splunk Usernames through the REST API in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the edit_user capability could create a native Splunk username that ends with a period. The vulnerability is possible because username validation does not reject a trailing period before the username is used for a user directory. This can cause distinct native Splunk usernames to share per-user configuration data, and user-management operations can affect the wrong account or fail. For more information see Set up native Splunk authentication and Define roles on the Splunk platform with capabilities in the Splunk documentation.
Bug ID: VULN-65732
CWE: CWE-20
CVSSv3.1 Score: 4.1, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76278: Authorization Bypass in SPL2 Module Permissions in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a user that holds a role with the edit_spl2_module_permissions capability could use the affected Representational State Transfer (REST) API to access permission grants for SPL2 modules that the user does not have permission to view. The vulnerability is possible because Splunk Enterprise does not verify that the user can read the requested app before the affected REST API returns SPL2 module permission grants. For more information see Module permissions and Manage SPL2 modules in the Splunk documentation.
Splunk Enterprise versions 9.4.x are not affected.
Bug ID: VULN-81959
CWE: CWE-639
CVSSv3.1 Score: 4.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Acknowledgments: Gabriel Nitu, Splunk
CVE-2026-76279: Improper Input Validation of Index Names through the collect Command in Splunk Enterprise
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, a user that holds a role with the run_collect capability could use the collect Search Processing Language (SPL) command to write events to internal indexes outside the index access configured for the role. The vulnerability is possible because Splunk Enterprise does not normalize whitespace in an index name before applying configured index-access restrictions for the role. For more information see collect, Define roles on the Splunk platform with capabilities, and How indexing works in the Splunk documentation.
Bug ID: VULN-79292
CWE: CWE-20
CVSSv3.1 Score: 4.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Mitigations and Workarounds
If upgrading to a fixed version is not possible, remove the run_collect capability from every role that does not have access to internal indexes. For more information see Define roles on the Splunk platform with capabilities in the Splunk documentation.
Acknowledgments: Anton (therceman)
CVE-2026-76280: Incorrect Permission Assignment for App Key Value Store Collections in Splunk Secure Gateway
Description
In Splunk Enterprise versions below 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions below 3.10.11, 3.9.25, and 3.8.72, an authenticated user who does not hold the “admin” or “sc_admin” Splunk roles could modify Splunk Secure Gateway alert and mobile-device recipient data in App Key Value Store (KV Store) collections that later alert and subscription workflows use. The vulnerability is possible because the affected collections allow unrestricted write access instead of limiting writes to authorized Splunk Secure Gateway workflows. For more information see About the app key value store, KV store endpoint descriptions, and About configuring role-based user access in the Splunk documentation.
Additional Solution
Upgrade Splunk Secure Gateway to versions 3.10.11, 3.9.25, and 3.8.72, or higher.
Bug ID: VULN-78747
CWE: CWE-732
CVSSv3.1 Score: 6.3, Medium
CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Mitigations and Workarounds
Turn off or remove the Splunk Secure Gateway app. See Manage app and add-on objects in the Splunk documentation. Note: Splunk Mobile, Spacebridge, and Mission Control rely on functionality in the Splunk Secure Gateway app. If you do not use any of these apps, features, or functionality, as a potential mitigation, you may turn off or remove the app.
Acknowledgments: M Mahdan Argya Syarif (0xbeludan)