Security Hardening in Splunk Enterprise - September/October 2026
Advisory ID: SVD-2026-1002
Published: 2026-10-07
Highest CVSSv3.1 Score: 9.8, Critical
Last Updated: 2026-10-07
Description
Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
Solution
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.
Product Status
| Product | Base Version | Affected Version | Fix Version |
|---|---|---|---|
| Splunk Enterprise | 10.4 | 10.4.0 to 10.4.2 | 10.4.3 |
| Splunk Enterprise | 10.2 | 10.2.0 to 10.2.6 | 10.2.7 |
| Splunk Enterprise | 10.0 | 10.0.0 to 10.0.9 | 10.0.10 |
| Splunk Enterprise | 9.4 | 9.4.0 to 9.4.14 | 9.4.15 |
Details
Each CVE groups findings in one CWE category. Its score is the highest CVSS score among those findings.
| CVE ID | Highest CVSS Score | Vulnerability Class (Highest-Level CWE) | Description |
|---|---|---|---|
| CVE-2026-76281 | 9.8 | CWE-284 | Improper Access Control |
| CVE-2026-76282 | 8.8 | CWE-664 | Improper Control of a Resource Through its Lifetime |
| CVE-2026-76283 | 7.6 | CWE-693 | Protection Mechanism Failure |
| CVE-2026-76284 | 9.0 | CWE-707 | Improper Neutralization |
| CVE-2026-76285 | 4.4 | CWE-710 | Improper Adherence to Coding Standards |