In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search… (CVE-2026-76338)
Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 contain a vulnerability where an unauthenticated user with access to a trusted distributed search private key can forge an administrative session token. This allows unauthorized access to data, potential system integrity compromise, and service disruption. The issue arises because the distributed search authentication token endpoint does not require signed requests to identify configured search peers, falling back to shared local key material.
AI Analysis
Technical Summary
CVE-2026-76338 affects Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. An unauthenticated attacker who has access to a trusted distributed search private key can exploit the lack of signed request enforcement at the distributed search authentication token endpoint. This enables forging of administrative session tokens, granting full access to relevant data, the ability to affect system integrity, and disrupt availability. The vulnerability stems from the endpoint's fallback to shared local key material when identifying configured search peers without requiring signed requests.
Potential Impact
Successful exploitation allows an unauthenticated attacker with access to the trusted distributed search private key to impersonate an administrator, access all relevant data, compromise system integrity, and disrupt service availability. This represents a high-severity risk to confidentiality, integrity, and availability of affected Splunk Enterprise deployments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to distributed search private keys to trusted personnel only and monitor for unauthorized access attempts. Review Splunk documentation on distributed search and authentication configuration to understand and potentially harden authentication token handling.
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has access to a trusted distributed search… (CVE-2026-76338)
Description
Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 contain a vulnerability where an unauthenticated user with access to a trusted distributed search private key can forge an administrative session token. This allows unauthorized access to data, potential system integrity compromise, and service disruption. The issue arises because the distributed search authentication token endpoint does not require signed requests to identify configured search peers, falling back to shared local key material.
CVSS v3.1
Score 8.1high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76338 affects Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. An unauthenticated attacker who has access to a trusted distributed search private key can exploit the lack of signed request enforcement at the distributed search authentication token endpoint. This enables forging of administrative session tokens, granting full access to relevant data, the ability to affect system integrity, and disrupt availability. The vulnerability stems from the endpoint's fallback to shared local key material when identifying configured search peers without requiring signed requests.
Potential Impact
Successful exploitation allows an unauthenticated attacker with access to the trusted distributed search private key to impersonate an administrator, access all relevant data, compromise system integrity, and disrupt service availability. This represents a high-severity risk to confidentiality, integrity, and availability of affected Splunk Enterprise deployments.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to distributed search private keys to trusted personnel only and monitor for unauthorized access attempts. Review Splunk documentation on distributed search and authentication configuration to understand and potentially harden authentication token handling.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2hhx-v97c-cm95
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-76338"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a870a8facd9273b49b5a1bc
Added to database: 08/20/2026, 14:09:19 UTC
Last enriched: 08/20/2026, 14:50:58 UTC
Last updated: 08/20/2026, 22:52:15 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.