CVE-2026-76313
Received Received - Intake

Remote Code Execution in Splunk Enterprise

Vulnerability report for CVE-2026-76313, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could perform Remote Code Execution (RCE) by uploading a malicious knowledge bundle and causing it to be used by distributed search, which can allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Representational State Transfer (REST) API endpoint for knowledge bundle upload does not require the high-privilege capability edit_dist_peer, and distributed search accepts caller-supplied knowledge bundle selections from users who do not hold that capability. For more information see What search heads send to search peers (https://help.splunk.com/en/splunk-enterprise/administer/distributed-search/9.2/knowledge-bundle-replication/what-search-heads-send-to-search-peers), About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.0/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access), Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/9.1/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities), and Using the REST API reference (https://help.splunk.com/en/splunk-enterprise/rest-api-reference/10.4/introduction/using-the-rest-api-reference) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
splunk splunk_enterprise to 10.4.2|end_excluding=10.2.6|end_excluding=10.0.9|end_excluding=9.4.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 allows a non-admin or non-power user to perform Remote Code Execution by uploading a malicious knowledge bundle. The bundle is then used by distributed search, granting access to all relevant data and compromising system integrity and availability.

Impact Analysis

An attacker could exploit this to execute arbitrary code on the Splunk Enterprise system, potentially leading to unauthorized data access, data breaches, system disruption, or complete system compromise. This affects confidentiality, integrity, and availability of the system and its data.

Compliance Impact

This vulnerability could lead to unauthorized access or exposure of sensitive data, violating compliance requirements such as GDPR (data protection) and HIPAA (health information privacy). Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance.

Mitigation Strategies

Upgrade Splunk Enterprise to a patched version (10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later) to address the RCE vulnerability in knowledge bundle handling.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76313. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart