CVE-2026-76319: The software does not perform an authorization check when an actor attempts to access a resource or perform an action. in Splunk Splunk Enterprise
Description
CVE-2026-76319 is a high-severity vulnerability in Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. It allows a low-privileged user without the fsh_manage capability to perform remote code execution via Federated Search bundle selection. This occurs because the system does not enforce authorization checks on the caller-controlled bundle selection in the Federated Search dispatch flow. Exploitation could lead to unauthorized access to data and compromise system integrity and availability.
CVSS v3.1
Score 8.8high
Affected software
Splunk
Splunk Enterprise
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In Splunk Enterprise versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a vulnerability exists due to missing authorization checks when a user attempts to select a Federated Search bundle. A low-privileged user lacking the fsh_manage capability can exploit this to execute remote code. The flaw arises because the Federated Search dispatch flow accepts caller-controlled bundle selection without enforcing the capability that manages federated providers and indexes, enabling unauthorized actions.
Potential Impact
An attacker with low privileges can achieve remote code execution, potentially gaining access to all relevant data and impacting system integrity and availability. This elevates the risk of data breaches and system compromise within affected Splunk Enterprise deployments.
Mitigation Recommendations
Splunk has released official fixes in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14 that address this vulnerability. Users should upgrade to these or later versions to remediate the issue. Refer to Splunk's official documentation on Federated Search security models and role capabilities for additional context. No alternative mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2026-08-19T12:02:03.625Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a862253acd9273b49a6fe0e
Added to database: 08/19/2026, 21:38:27 UTC
Last enriched: 09/11/2026, 04:17:26 UTC
Last updated: 10/04/2026, 10:04:21 UTC
Views: 40
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.