Skip to content

CVE-2026-76310

Splunk Enterprise embedded report access control flaw lets unauthenticated users take administrative actions (CVE-2026-76310)

Critical 9.4 Vendor: Cisco Published

Splunk Enterprise 9.4, 10.0, 10.2 and 10.4 before fixed builds have a critical access control flaw. An unauthenticated user with an embedded report token can recover session material and act with the report owner's privileges, including admin. Update to 9.4.14, 10.0.9, 10.2.6 or 10.4.2.

What happened

Splunk Enterprise does not block REST API dispatch archive download requests made through embedded report access. An unauthenticated user who holds an embedded report token can download the search job dispatch archive associated with that report. The archive can contain session material.

With that session material, the user can access the data available to the report owner. If the owner holds the Splunk "admin" role, the user can also take administrative actions that affect system integrity. The CVSS vector rates the issue as network-reachable with low attack complexity and no user interaction, with high confidentiality and integrity impact.

No exploitation of this CVE is recorded, and the data provided marks it as not publicly disclosed.

Who is affected

Affected releases are Splunk Enterprise 10.4 before 10.4.2, 10.2 before 10.2.6, 10.0 before 10.0.9, and 9.4 before 9.4.14. Embedded reports are the relevant feature: the weakness matters where embedded report tokens are issued and a report owner holds elevated Splunk privileges, particularly the admin role.

What to do now

  1. Identify Splunk Enterprise instances running 9.4 before 9.4.14, 10.0 before 10.0.9, 10.2 before 10.2.6, or 10.4 before 10.4.2.
  2. Upgrade to the matching fixed release: Splunk Enterprise 9.4.14, 10.0.9, 10.2.6 or 10.4.2.
  3. If you cannot patch immediately, review embedded report token issuance and the roles assigned to report owners, focusing on any owner with the admin role. No separate vendor workaround is listed.

How to detect it

No specific indicators of compromise are provided in the data available. Monitor REST API access for dispatch archive download requests tied to embedded report tokens, particularly from unexpected clients or outside normal reporting periods, and review privileged actions taken by report owners after such downloads.

Beyond the patch

This is the kind of network-reachable access control flaw that exposure management should catch. Because the path does not require prior authentication beyond possession of an embedded report token, our Virtual CISO Services (vCISO) can help you find and reduce Splunk Enterprise exposure. And because your real exposure window is set by how quickly Splunk releases and you deploy a fix, tracking the vendor software you run belongs in Supply Chain Defense & Third-Party Risk.

Affected and fixed versions

ProductAffectedFixed in
Splunk Enterprise10.4 – < 10.4.2
10.2 – < 10.2.6
10.0 – < 10.0.9
9.4 – < 9.4.14
10.4.2
10.2.6
10.0.9
9.4.14

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.