CVE-2026-76282
Received
Received - Intake
Memory Corruption in Splunk Enterprise
Vulnerability report for CVE-2026-76282, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-07
Last updated on: 2026-10-07
Assigner: Cisco Systems, Inc.
Description
Description
Improper Control of a Resource Through its Lifetime. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Splunk | Splunk | Enterprise 10.4 |
| Splunk | Splunk | Enterprise 10.2 |
| Splunk | Splunk | Enterprise 10.0 |
| Splunk | Splunk | Enterprise 9.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-664 | The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release. |