SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-76348

LOW · CVSS 3.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

In Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, users with the high-privilege list_search_head_clustering capability can exploit control endpoints to alter the cluster state, potentially leading to a denial of service. This vulnerability arises from insufficient validation of HTTP request types for state-changing operations. Organizations using affected versions, particularly those with users holding elevated privileges, should prioritize patching to mitigate the risk of service disruption.

CVE
CVE-2026-76348
Severity
LOW
CVSS
3.8
EPSS
0.23%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Cluster member control endpoints and change cluster state, which could allow for a denial of service. The vulnerability is possible because the Search Head Cluster member control endpoints do not require a state-changing Hypertext Transfer Protocol (HTTP) request type before they apply read-only authorization.

Related CVEs

Other vulnerabilities affecting the same vendor(s)