Skip to content

CVE-2026-76312

Splunk Enterprise embedded reports improper access control lets unauthenticated users access data (CVE-2026-76312)

Critical 9.4 Vendor: Cisco Published

Splunk Enterprise 9.4, 10.0, 10.2 and 10.4 before the patched builds has improper access control in embedded reports. An unauthenticated user who can read the HTML source of an embedding page could reuse exposed session material to access data and affect integrity. Apply the fixed releases.

What happened

Splunk Enterprise has an improper access control flaw in the dispatch archive download path for embedded reports. The embedded-report authorization boundary is not correctly enforced, and archived search-job data includes sensitive session material. An unauthenticated user who can read the HTML source of a page that embeds a Splunk report can use that session material to access all relevant data and affect system integrity. The flaw is network-reachable, requires no privileges or user interaction, and is rated critical with a CVSS 3.1 score of 9.4, with high confidentiality and integrity impact and low availability impact.

No exploitation or public disclosure is recorded in the source, and the CVE is not listed in CISA KEV. The available fix should be applied without waiting for proof-of-concept code.

Who is affected

Affected product and version ranges:

  • Splunk Enterprise 10.4 to before 10.4.1
  • Splunk Enterprise 10.2 to before 10.2.6
  • Splunk Enterprise 10.0 to before 10.0.9
  • Splunk Enterprise 9.4 to before 9.4.14

Deployments are exposed when Splunk reports are embedded into pages or portals and an unauthenticated user can read the HTML source of one of those pages. This is most relevant where embedded reports are used on internet-facing or shared pages.

What to do now

  1. Apply the vendor fix. Upgrade Splunk Enterprise to one of the fixed versions: 10.4.1, 10.2.6, 10.0.9, or 9.4.14, matching your current branch.
  2. Until the upgrade is complete, restrict or remove unauthenticated access to any page that embeds Splunk reports. This reduces the chance that the HTML source exposing session material can be read; it is a containment measure, not a substitute for patching.
  3. After upgrading, review Splunk's documentation for additional configuration for embedded reports and embed scheduled reports to confirm your configuration is correct.

How to detect it

The source does not provide vendor-detailed indicators of compromise. As an operational check, identify pages that embed Splunk reports and verify whether an unauthenticated user can retrieve their HTML source; that exposure is the precondition for this vulnerability. Where possible, log and review access to the dispatch archive download path.

Beyond the patch

This is a pre-authentication, network-reachable flaw in a platform many organisations use for log management and reporting, so the right long-term control is continuous exposure visibility: know which Splunk deployments and embedded-report pages are reachable without credentials, and fix them before an attacker does. Virtual CISO Services (vCISO) can help you maintain that exposure inventory and prioritise remediation. Because suppliers' patch cycles set your exposure window, Supply Chain Defense & Third-Party Risk helps you track Splunk's fix cadence and identify the deployments still waiting for this update.

Affected and fixed versions

ProductAffectedFixed in
Splunk Enterprise10.4 – < 10.4.1
10.2 – < 10.2.6
10.0 – < 10.0.9
9.4 – < 9.4.14
10.4.1
10.2.6
10.0.9
9.4.14

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.