LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-76317

splunk · splunk

Published
CVSS8.8
Severityhigh
WeaknessCWE-26
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power" Splunk roles could move files that the user account running Splunk Enterprise can read into a lookup that the user controls. The user could then access all relevant data and affect system integrity and availability on the search head. The vulnerability is possible because the lookup configuration endpoint does not resolve lookup source paths before checking whether they stay inside the allowed lookup staging area. For more information see About lookups (https://help.splunk.com/en/splunk-enterprise/manage-knowledge-objects/knowledge-management-manual/10.4/use-lookups-in-splu

References

← Back to the CVE Tracker

Our coverage of CVE-2026-76317

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-76317.