CVE-2026-76319
Analyzed Analyzed - Analysis Complete

Remote Code Execution in Splunk Enterprise via Federated Search

Vulnerability report for CVE-2026-76319, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-27

Assigner: Cisco Systems, Inc.

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_manage capability could perform Remote Code Execution through Federated Search bundle selection. This could allow for access to all relevant data and affect system integrity and availability. The vulnerability is possible because the Federated Search dispatch flow accepts caller-controlled bundle selection without enforcing the capability that manages federated providers and indexes. For more information see Security models for Federated Search for Splunk (https://help.splunk.com/en/splunk-enterprise/search/federated-search/10.4/run-federated-searches-across-other-splunk-deployments/service-accounts-and-security-for-federated-search-for-splunk/security-models-for-federated-search-for-splunk) and Define roles on the Splunk platform with capabilities (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.4/manage-splunk-platform-users-and-roles/define-roles-on-the-splunk-platform-with-capabilities) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-27
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
splunk splunk From 10.0.0 (inc) to 10.0.9 (exc)
splunk splunk From 10.2.0 (inc) to 10.2.6 (exc)
splunk splunk From 10.4.0 (inc) to 10.4.2 (exc)
splunk splunk From 9.4.0 (inc) to 9.4.14 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14. A low-privileged user without the fsh_manage capability can perform Remote Code Execution through Federated Search bundle selection. The issue arises because the Federated Search flow accepts user-controlled bundle selection without enforcing the required capability for managing federated providers and indexes.

Detection Guidance

To detect this vulnerability, check Splunk Enterprise version against patched versions (10.4.2, 10.2.6, 10.0.9, 9.4.14). Verify user roles lack the fsh_manage capability. Inspect Federated Search bundle selections for unauthorized access patterns.

Impact Analysis

This vulnerability could allow an attacker to execute arbitrary code remotely, potentially gaining access to all relevant data. It may also compromise system integrity and availability by allowing unauthorized actions through the exploited Federated Search feature.

Compliance Impact

This vulnerability could allow unauthorized access to sensitive data, potentially violating GDPR's data protection principles and HIPAA's confidentiality requirements. Unauthorized remote code execution may lead to data breaches, impacting compliance with these regulations.

Mitigation Strategies

Upgrade Splunk Enterprise to a patched version (10.4.2, 10.2.6, 10.0.9, or 9.4.14 or later) to address the vulnerability. Ensure low-privileged users do not have the fsh_manage capability unless explicitly required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76319. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart