Security Hardening in Splunk Enterprise - September/October 2026

Advisory ID: SVD-2026-1002

Published: 2026-10-07

Highest CVSSv3.1 Score: 9.8, Critical

Last Updated: 2026-10-07

Description

Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.

Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk Enterprise10.410.4.0 to 10.4.210.4.3
Splunk Enterprise10.210.2.0 to 10.2.610.2.7
Splunk Enterprise10.010.0.0 to 10.0.910.0.10
Splunk Enterprise9.49.4.0 to 9.4.149.4.15

Details

Each CVE groups findings in one CWE category. Its score is the highest CVSS score among those findings.

CVE IDHighest CVSS ScoreVulnerability Class (Highest-Level CWE)Description
CVE-2026-762819.8 CWE-284Improper Access Control
CVE-2026-762828.8 CWE-664Improper Control of a Resource Through its Lifetime
CVE-2026-762837.6 CWE-693Protection Mechanism Failure
CVE-2026-762849.0 CWE-707Improper Neutralization
CVE-2026-762854.4 CWE-710Improper Adherence to Coding Standards