SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76338

HIGH · CVSS 8.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are vulnerable to an attack that allows unauthenticated users with access to a trusted distributed search private key to forge administrative session tokens. This can lead to unauthorized access to sensitive data, compromise system integrity, and disrupt service availability. Organizations using affected versions should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-76338
Severity
HIGH
CVSS
8.1
EPSS
0.27%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search private key could forge an administrative session token, access all relevant data, affect system integrity, and disrupt service availability. The vulnerability is possible because the distributed search authentication token endpoint does not require a signed request to identify a configured search peer, allowing the request to fall back to shared local key material. For more information see About distributed search (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/10.4/overview-of-distributed-search/about-distributed-search) and authentication.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.2-configuration-file-reference/authentication.conf) in Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)