Skip to content

CVE-2026-76284

Splunk Enterprise improper neutralization allows unauthenticated network compromise (CVE-2026-76284)

Critical 9.8 Vendor: Cisco Published

Splunk Enterprise 9.4, 10.0, 10.2 and 10.4 are affected by an improper neutralization weakness rated critical. An unauthenticated network attacker can affect confidentiality, integrity and availability. Patch to 10.4.3, 10.2.7, 10.0.10 or 9.4.15.

What happened

The CVE record assigns this flaw CWE-707, Improper Neutralization. Splunk has stated that it addressed multiple internally identified vulnerabilities in Splunk Enterprise releases 10.4.3, 10.2.7, 10.0.10, and 9.4.15, grouping them by Common Weakness Enumeration. This CVE covers the CWE-707 group. The sources do not state a more specific affected component or attack technique.

The CVSS 3.1 base score is 9.8, rated critical. In practice the vector means an attacker can reach the weakness over the network without any credentials or user interaction, and successful exploitation would have high impact on confidentiality, integrity, and availability. The CVE record and associated sources do not indicate public disclosure or active exploitation, and the flaw is not listed in CISA's KEV catalogue.

Who is affected

Splunk Enterprise release lines from 10.4 to before 10.4.3, 10.2 to before 10.2.7, 10.0 to before 10.0.10, and 9.4 to before 9.4.15 are affected. This includes all deployments of those lines that have not been updated to the fixed release in their branch. Splunk Enterprise is commonly deployed as a central log analytics, search, and security monitoring platform, so affected instances may hold sensitive operational data and often sit in networks where many systems and administrators connect into them. Because the CVSS vector is network-reachable, any instance exposed beyond trusted management segments should be prioritised for patching.

What to do now

  1. Patch first. Upgrade each affected Splunk Enterprise instance to the matching fixed release: 10.4.3 for the 10.4 line, 10.2.7 for the 10.2 line, 10.0.10 for the 10.0 line, and 9.4.15 for the 9.4 line.
  2. Read Splunk's advisory for the release notes and any installation guidance. No workaround has been published, so patching should be treated as the primary control.
  3. While you plan the update, restrict network access to Splunk Enterprise so instances are reachable only from trusted management and operations networks. This is containment, not a substitute for patching.

Beyond the patch

This is a network-reachable, no-credential weakness, so the practical risk is highest for Splunk Enterprise instances exposed beyond their intended management boundary. Virtual CISO Services can help build the external and internal exposure view that catches reachable services before an advisory arrives; Supply Chain Defense & Third-Party Risk helps keep sight of the software suppliers and release cadences that determine your window of exposure.

Affected and fixed versions

ProductAffectedFixed in
Splunk Enterprise10.4 – < 10.4.3
10.2 – < 10.2.7
10.0 – < 10.0.10
9.4 – < 9.4.15
10.4.3
10.2.7
10.0.10
9.4.15

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.