SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76337

MEDIUM · CVSS 5.3 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to unauthorized access, allowing unauthenticated users to read JavaScript files located outside the designated static directory. This exposure could lead to information disclosure, potentially revealing sensitive data or application logic. Organizations using affected versions should prioritize remediation to mitigate the risk of unauthorized data access.

CVE
CVE-2026-76337
Severity
MEDIUM
CVSS
5.3
EPSS
0.30%
Java

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user could read JavaScript files outside the Splunk Web static directory. The vulnerability is possible because Splunk Web does not restrict static file requests to the configured static directory.

Related CVEs

Other vulnerabilities affecting the same vendor(s)