CVE-2026-76311
Splunk Enterprise embedded report access control lets unauthenticated users download dispatch archives (CVE-2026-76311)
Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, and 9.4.14 has an improper access control flaw in embedded report dispatch archives. An unauthenticated user with an embedded report token can download an archive and use exposed session material to access data and affect integrity. Upgrade now.
What happened
Splunk Enterprise's embedded report authorization flow does not block dispatch archive download requests before the platform begins sending the archive. An unauthenticated user who holds an embedded report token can therefore download the dispatch archive for an embedded report search job. The archive contains exposed session material that can then be used to access all relevant data on the instance and affect system integrity.
The vulnerability is reachable over the network with low attack complexity. No prior authentication or user interaction is required beyond having an embedded report token. The CVSS 3.1 score is 9.4 (critical), with high confidentiality and integrity impact and low availability impact.
The record does not state that this vulnerability is being exploited in the wild, and it is not listed in CISA KEV. No vendor statement on exploitation is provided.
Who is affected
Affected versions are Splunk Enterprise 10.4 prior to 10.4.2, 10.2 prior to 10.2.6, 10.0 prior to 10.0.9, and 9.4 prior to 9.4.14. The flaw concerns embedded report dispatch archives, so deployments that use embedded reports or distribute embedded report tokens are directly exposed. Organisations running any of these affected version ranges should review their Splunk Enterprise instances and reporting integrations.
What to do now
- Upgrade Splunk Enterprise to a fixed release: 10.4.2, 10.2.6, 10.0.9, or 9.4.14, depending on your current branch. The record confirms a fix is available.
- No vendor workaround is listed in the record. If you cannot patch immediately, restrict network access to the Splunk Enterprise instance and monitor for unusual dispatch archive download activity.
- Confirm which Splunk Enterprise instances and embedded report integrations are in use, and ensure that exposed reporting or management interfaces are reachable only from trusted networks.
How to detect it
The record does not provide vendor-issued indicators of compromise. Because the vulnerability is exercised through dispatch archive download requests using an embedded report token, review access to Splunk Enterprise for dispatch archive downloads from unexpected network sources, particularly on affected versions.
Beyond the patch
This is a network-reachable access-control flaw in a product that often holds sensitive operational data. The exposure is not only this CVE, but whether affected Splunk Enterprise instances and embedded report endpoints are reachable by unauthorised users at all. Virtual CISO Services can help you map and reduce that exposed surface, while Supply Chain Defense & Third-Party Risk can help you track the affected Splunk Enterprise versions in your estate and the vendor patch cycle that sets your exposure window.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Splunk Enterprise | 10.4 – < 10.4.2 10.2 – < 10.2.6 10.0 – < 10.0.9 9.4 – < 9.4.14 | 10.4.2 10.2.6 10.0.9 9.4.14 |