SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76352

HIGH · CVSS 8.8 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

In Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14, users lacking "admin" or "power" roles can exploit unsecured generic configuration endpoints to create or modify scripted lookups, potentially accessing sensitive data and compromising system integrity. This high-severity vulnerability necessitates immediate attention from organizations using affected versions of Splunk Enterprise to mitigate risks associated with unauthorized data access and operational disruption.

CVE
CVE-2026-76352
Severity
HIGH
CVSS
8.8
EPSS
0.25%

Original NVD Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could create or modify a scripted lookup through generic configuration endpoints and run an installed lookup script with the permissions of the user account running Splunk Enterprise, which could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the generic transforms configuration endpoints do not enforce the capabilities required to create or edit external lookup definitions. For more information see Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) and limits.conf (https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.4/configuration-file-reference/10.4.2-configuration-file-reference/limits.conf) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)