Threats Tagged 'cve-2026-76353'
View all threats tagged with 'cve-2026-76353'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-76353'
Click on any threat for detailed analysis and mitigation recommendations
Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14 contain a vulnerability where non-admin and non-power users can submit crafted knowledge bundle deltas to delete arbitrary files accessible to the cluster manager. This flaw arises because the knowledge bundle delta processing does not restrict file removal paths to the staging directory and lacks proper authorization enforcement. The vulnerability can impact system integrity and disrupt service availability. Join the discussion | GCVE Database | 08/20/2026, 00:35:01 UTC Added: 08/20/2026, 14:09:18 UTC |
CVE-2026-76353 is a path traversal vulnerability in Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14. It allows users without admin or power roles to submit crafted knowledge bundle deltas that can delete arbitrary files accessible to the cluster manager. This occurs because the software does not properly restrict removal paths to the staging directory and fails to enforce authorization boundaries on the endpoint. The vulnerability can impact system integrity and disrupt service. Join the discussion | CVE Database V5 | 08/19/2026, 21:34:46 UTC Added: 08/19/2026, 21:38:33 UTC |
Showing 1 to 2 of 2 results