CVE-2026-76344
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could write dispatch metadata to an arbitrary location on the host by supplying a crafted search identifier to a Representational State Transfer (REST) API endpoint and affect system integrity on the host. The vulnerability is possible because Splunk Enterprise does not validate the search identifier before using it to create a dispatch directory. For more information see About configuring role-based user access (https://help.splunk.com/en/splunk-enterprise/administer/manage-users-and-security/10.2/manage-splunk-platform-users-and-roles/about-configuring-role-based-user-access) in the Splunk documentation.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- EPSS probability
- 0.30%
- CWE
- CWE-27
- Published
- 2026-08-19
- Last modified
- 2026-08-26
Affected products
- Splunk Splunk Enterprise
- Splunk Splunk Enterprise
- Splunk Splunk Enterprise
- Splunk Splunk Enterprise
Weakness type
Related vulnerabilities
- CVE-2026-62391 — Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases
- CVE-2026-24457 — An unsafe parsing of OpenMQ's configuration, allows a remote attacker to read arbitrary files from...
- CVE-2026-20018 — Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerability
- CVE-2025-66518 — Apache Kyuubi: Unauthorized directory access due to missing path normalization
- CVE-2025-58292 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this...
- CVE-2025-10438 — Path Traversal in Yordam BT's Yordam Katalog
- CVE-2025-58761 — Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`
- CVE-2024-43658 — Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.