Skip to content

CVE-2026-76311

Splunk Enterprise embedded report access control lets unauthenticated users download dispatch archives (CVE-2026-76311)

Critical 9.4 Vendor: Cisco Published

Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, and 9.4.14 has an improper access control flaw in embedded report dispatch archives. An unauthenticated user with an embedded report token can download an archive and use exposed session material to access data and affect integrity. Upgrade now.

What happened

Splunk Enterprise's embedded report authorization flow does not block dispatch archive download requests before the platform begins sending the archive. An unauthenticated user who holds an embedded report token can therefore download the dispatch archive for an embedded report search job. The archive contains exposed session material that can then be used to access all relevant data on the instance and affect system integrity.

The vulnerability is reachable over the network with low attack complexity. No prior authentication or user interaction is required beyond having an embedded report token. The CVSS 3.1 score is 9.4 (critical), with high confidentiality and integrity impact and low availability impact.

The record does not state that this vulnerability is being exploited in the wild, and it is not listed in CISA KEV. No vendor statement on exploitation is provided.

Who is affected

Affected versions are Splunk Enterprise 10.4 prior to 10.4.2, 10.2 prior to 10.2.6, 10.0 prior to 10.0.9, and 9.4 prior to 9.4.14. The flaw concerns embedded report dispatch archives, so deployments that use embedded reports or distribute embedded report tokens are directly exposed. Organisations running any of these affected version ranges should review their Splunk Enterprise instances and reporting integrations.

What to do now

  1. Upgrade Splunk Enterprise to a fixed release: 10.4.2, 10.2.6, 10.0.9, or 9.4.14, depending on your current branch. The record confirms a fix is available.
  2. No vendor workaround is listed in the record. If you cannot patch immediately, restrict network access to the Splunk Enterprise instance and monitor for unusual dispatch archive download activity.
  3. Confirm which Splunk Enterprise instances and embedded report integrations are in use, and ensure that exposed reporting or management interfaces are reachable only from trusted networks.

How to detect it

The record does not provide vendor-issued indicators of compromise. Because the vulnerability is exercised through dispatch archive download requests using an embedded report token, review access to Splunk Enterprise for dispatch archive downloads from unexpected network sources, particularly on affected versions.

Beyond the patch

This is a network-reachable access-control flaw in a product that often holds sensitive operational data. The exposure is not only this CVE, but whether affected Splunk Enterprise instances and embedded report endpoints are reachable by unauthorised users at all. Virtual CISO Services can help you map and reduce that exposed surface, while Supply Chain Defense & Third-Party Risk can help you track the affected Splunk Enterprise versions in your estate and the vendor patch cycle that sets your exposure window.

Affected and fixed versions

ProductAffectedFixed in
Splunk Enterprise10.4 – < 10.4.2
10.2 – < 10.2.6
10.0 – < 10.0.9
9.4 – < 9.4.14
10.4.2
10.2.6
10.0.9
9.4.14

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.